Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors brotherhood

Description

Brotherhood is a ransomware group that emerged in late 2025, targeting organizations in the US, Canada, and Australia across manufacturing, communications, and construction sectors, operating a Tor-based double-extortion leak site. Known victims: 18

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

The Brotherhood is a medium-sophistication ransomware group targeting US, Canada, and Australia across manufacturing, communications, and construction sectors. They use Tor-based double-extortion tactics, marking them as a growing threat to critical infrastructure and financial interests.

Goals & Targeting

The Brotherhood targets sectors with high infrastructure value and data-sensitive industries to maximize financial gains. Their geographic spread across US, Canada, and Australia suggests a strategy to diversify attacks and reduce detection risks.

Enhanced Description

The Brotherhood emerged in late 2025, operating in the US, Canada, and Australia, focusing on制造业,通信和建筑行业。他们采用双 extortion策略,使用Tor网站作为沟通渠道,对受害者施加压力以获取赎金。该组织已知有18个受害者,显示出其在运营上的一定能力。

Key Capabilities

  • Ransomware deployment
  • Double extortion tactics
  • Phishing campaigns

MITRE ATT&CK Tactics

Exfiltration
Ransomware Deployment

ATT&CK Techniques

T1059
T1566.002

Software / Tooling

Custom ransomware family
Tor communication tools

Campaigns & Victims

The Brotherhood operates with a steady tempo, targeting mid-sized to large organizations in their sectors. Their campaigns involve spear-phishing and malicious links distribution. Notable operations include multiple attacks in manufacturing and communications spaces.

IOC Patterns

  • Spear phishing emails
  • Malicious Tor traffic
  • Ransomware binaries

Recommended Actions

  • Enhance email filtering
  • Educate employees on phishing
  • Monitor network for extortion attempts

Suggested Tags

ransomware
financial-gain
mid-market

Confidence Assessment

Moderate confidence with limited data on TTPs and full scope.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
ransomware
financial-gain
mid-market

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Apr 4, 2025
Last Seen
Jan 6, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.