Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors braincipher

Description

Brain Cipher emerged in July 2024. Both Windows and Linux variants are available. Brain Cipher using the leaked build of LockBit Black for their operations. The group suspected to have exploited CVE-2023-28252 (Microsoft Windows CLFS Driver Privilege Escalation Vulnerability). The Ransom demand ranges from $150,000 to $1,00,0000. Demand to be paid with Monero (XMR) cryptocurrency. In 2025, they have shifted their new Negotiation portal to new server with vanity TOR Domain starting with 'brain'. Known victims: 54 3 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

BrainCipher is a medium-sophistication criminal threat actor specializing in ransomware attacks. Emerging in July 2024, they have targeted various industries, leveraging known vulnerabilities like CVE-2023-28252 and using LockBit Black malware. Their campaigns involve spear-phishing attacks and encrypted communication channels, seeking significant financial gains through organizational disruption.

Goals & Targeting

BrainCipher's primary motivation is financial gain through ransomware operations targeting organizations with critical data and infrastructure. Their strategic objectives include disrupting business continuity and extorting large sums from victims. Typically, they target mid-sized to large organizations across various sectors such as healthcare, automotive, and finance, suggesting a focus on industries where downtime or data loss would have significant consequences.

Enhanced Description

BrainCipher, a relatively new ransomware group active since July 2024, has demonstrated moderate technical sophistication in their operations. Known for targeting both Windows and Linux systems, they have employed a leaked version of the LockBit Black ransomware to further their objectives. Their campaigns are characterized by precision attacks across various sectors, including healthcare, automotive, and financial services, with a focus on demanding significant ransoms ranging from $150,000 to $1 million in Monero cryptocurrency. BrainCipher's operational strategy involves shifting infrastructure over time, exemplified by their adoption of a new negotiation portal hosted on a vanity TOR domain starting with 'brain'. This strategic shift underscores their adaptability and focus on maintaining communication channels to facilitate extortion. Their activities highlight the evolving nature of ransomware groups, which increasingly rely on sophisticated tools and techniques to maximize their financial gain while avoiding detection.

Key Capabilities

  • Ransomware deployment (LockBit Black variant)
  • Exploitation of CVE-2023-28252
  • Spear-phishing campaigns using macro-laced Office documents
  • Encrypted communication channels for C2
  • Domain-fronting techniques for obfuscation

MITRE ATT&CK Tactics

Initial Access
Execution
Communication
Defense Evasion
Discovery

ATT&CK Techniques

T1064.001: Exploitation of CVE-2023-28252 (Windows CLFS Driver)
T1059.002: Office Document Macros
T1071: Internal Domain Communication over Custom Protocol
T1036: Encrypted Network Communication
T1566.001: Obfuscated Domain Name

Software / Tooling

LockBit Black ransomware
Cobalt Strike (potential)
RansomEXX (similar family)

Campaigns & Victims

BrainCipher has demonstrated an operational pattern of precision attacks, leveraging known vulnerabilities and sophisticated TTPs. Their shift to a new negotiation portal, hosted on a vanity TOR domain starting with 'brain', indicates efforts to maintain operational persistence and avoid detection. Campaigns have targeted diverse industries, suggesting a strategic focus on maximizing disruption across sectors.

IOC Patterns

  • Spear-phishing emails from domains like 'cyberfear.com'
  • MD5 Hashes of their malware samples
  • Encrypted communications over custom protocols
  • Domain-fronting activities
  • Presence of LockBit Black files

Recommended Actions

  • Implement strict email filtering to detect spear-phishing attempts
  • Monitor for known exploit activity in CVE-2023-28252
  • Encrypt sensitive data and maintain offline backups
  • Enhance network monitoring for domain-fronting activities
  • Educate employees on recognizing phishing tactics

Suggested Tags

APT
ransomware
financial-gain
healthcare
critical-infrastructure

Confidence Assessment

Confidence in BrainCipher's intelligence is high due to known campaigns and indicators. However, gaps exist regarding their exact targeting countries and detailed TTPs beyond observed hashes and emails.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

Email Address 3 MD5 Hash 12

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

25

Campaigns

15

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial Targeting
APT
ransomware
financial-gain
healthcare
critical-infrastructure

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jul 1, 2024
Last Seen
Jul 22, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.