Brotherhood is a ransomware group that emerged in late 2025, targeting organizations in the US, Canada, and Australia across manufacturing, communications, and construction sectors, operating a Tor-based double-extortion leak site. Known victims: 18
Objectives
Executive Summary
The Brotherhood is a medium-sophistication ransomware group targeting US, Canada, and Australia across manufacturing, communications, and construction sectors. They use Tor-based double-extortion tactics, marking them as a growing threat to critical infrastructure and financial interests.
Goals & Targeting
The Brotherhood targets sectors with high infrastructure value and data-sensitive industries to maximize financial gains. Their geographic spread across US, Canada, and Australia suggests a strategy to diversify attacks and reduce detection risks.
Enhanced Description
The Brotherhood emerged in late 2025, operating in the US, Canada, and Australia, focusing on制造业,通信和建筑行业。他们采用双 extortion策略,使用Tor网站作为沟通渠道,对受害者施加压力以获取赎金。该组织已知有18个受害者,显示出其在运营上的一定能力。
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Brotherhood operates with a steady tempo, targeting mid-sized to large organizations in their sectors. Their campaigns involve spear-phishing and malicious links distribution. Notable operations include multiple attacks in manufacturing and communications spaces.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence with limited data on TTPs and full scope.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics