CiphBit is a ransomware-as-a-service group active since April 2023, targeting small-to-mid-sized businesses across the UK, Europe, and North America with 38 known victims, employing a data-broker model with selective free leaks to pressure victims alongside standard double extortion. Known victims: 36 1 ransom note(s) on file
Objectives
Executive Summary
CiphBit is a medium-tier ransomware-as-a-service (RaaS) group primarily targeting small-to-mid-sized businesses across the UK, Europe, and North America since April 2023. They employ double extortion tactics and a data-broker model, using selective free leaks to pressure victims into paying ransoms. Their operations demonstrate a clear focus on financial gain through ransomware activities.
Goals & Targeting
CiphBit's primary objectives are organizational gain and financial profit, achieved through ransomware attacks and double extortion schemes. They target small-to-mid-sized businesses in sectors that are less likely to have robust cybersecurity measures, such as healthcare, education, and local businesses. Their geographic focus on the UK, Europe, and North America suggests a strategic choice of regions with higher cyberattack success rates and potentially lower law enforcement scrutiny. By focusing on these regions, CiphBit maximizes their chances of successful ransom payments while maintaining operational efficiency.
Enhanced Description
CiphBit operates as a financially motivated criminal group specializing in ransomware attacks. Since their emergence in April 2023, they have targeted over 36 small-to-mid-sized businesses, leveraging both encryption and data exfiltration to pressure victims into paying ransoms. Unlike some high-profile ransomware groups, CiphBit has not gained significant media attention, likely due to their focus on specific geographic regions and their relatively lower number of victims. Their use of a data-broker model, where they sell stolen data instead of just encrypting it, adds an additional layer of pressure on their targets. This approach underscores their strategic focus on maximizing financial returns while minimizing the risks associated with larger-scale operations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CiphBit has demonstrated consistent activity since their first appearance in April 2023, with a notable focus on small businesses across specific regions. Their campaigns often involve initial phishing or social engineering to compromise victim networks before deploying ransomware and exfiltrating data. A notable tactic is the selective release of stolen data to pressure victims into paying ransoms without fully encrypting all data first. This approach reduces risk by ensuring some immediate financial return even if negotiations fail.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
There is medium confidence in the details provided about CiphBit. While their operational model, targeting patterns, and double extortion tactics are well-documented, specific technical details such as exact tools used, kill chains, and full list of victims remain limited. Further intelligence on their TTPs and victimology could enhance defensive strategies.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics