Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ciphbit

Description

CiphBit is a ransomware-as-a-service group active since April 2023, targeting small-to-mid-sized businesses across the UK, Europe, and North America with 38 known victims, employing a data-broker model with selective free leaks to pressure victims alongside standard double extortion. Known victims: 36 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

CiphBit is a medium-tier ransomware-as-a-service (RaaS) group primarily targeting small-to-mid-sized businesses across the UK, Europe, and North America since April 2023. They employ double extortion tactics and a data-broker model, using selective free leaks to pressure victims into paying ransoms. Their operations demonstrate a clear focus on financial gain through ransomware activities.

Goals & Targeting

CiphBit's primary objectives are organizational gain and financial profit, achieved through ransomware attacks and double extortion schemes. They target small-to-mid-sized businesses in sectors that are less likely to have robust cybersecurity measures, such as healthcare, education, and local businesses. Their geographic focus on the UK, Europe, and North America suggests a strategic choice of regions with higher cyberattack success rates and potentially lower law enforcement scrutiny. By focusing on these regions, CiphBit maximizes their chances of successful ransom payments while maintaining operational efficiency.

Enhanced Description

CiphBit operates as a financially motivated criminal group specializing in ransomware attacks. Since their emergence in April 2023, they have targeted over 36 small-to-mid-sized businesses, leveraging both encryption and data exfiltration to pressure victims into paying ransoms. Unlike some high-profile ransomware groups, CiphBit has not gained significant media attention, likely due to their focus on specific geographic regions and their relatively lower number of victims. Their use of a data-broker model, where they sell stolen data instead of just encrypting it, adds an additional layer of pressure on their targets. This approach underscores their strategic focus on maximizing financial returns while minimizing the risks associated with larger-scale operations.

Key Capabilities

  • Ransomware-as-a-Service (RaaS) operations
  • Double extortion tactic
  • Data-broker model for pressure
  • Spear-phishing campaigns
  • Email compromise techniques
  • Lateral movement within networks

MITRE ATT&CK Tactics

Attack Execution
Credential Access
Discovery

ATT&CK Techniques

T1566.002
T1059.003
T1566.001
T1036.001

Software / Tooling

CiphBit Ransomware
Phishing Tools (e.g., malicious email templates)

Campaigns & Victims

CiphBit has demonstrated consistent activity since their first appearance in April 2023, with a notable focus on small businesses across specific regions. Their campaigns often involve initial phishing or social engineering to compromise victim networks before deploying ransomware and exfiltrating data. A notable tactic is the selective release of stolen data to pressure victims into paying ransoms without fully encrypting all data first. This approach reduces risk by ensuring some immediate financial return even if negotiations fail.

IOC Patterns

  • Spear-phishing emails targeting small businesses
  • Encrypted files with .ciphbit extensions
  • Internal network lateral movement
  • Use of compromised email accounts for C2

Recommended Actions

  • Implement comprehensive phishing awareness training for employees
  • Enhance network segmentation to limit lateral movement
  • Regularly back up critical data and store copies offline
  • Monitor email traffic for signs of compromise or external communication
  • Deploy endpoint detection and response (EDR) solutions to detect and mitigate ransomware activities

Suggested Tags

ransomware
financial-motivation
business-targeting
cybercriminal

Confidence Assessment

There is medium confidence in the details provided about CiphBit. While their operational model, targeting patterns, and double extortion tactics are well-documented, specific technical details such as exact tools used, kill chains, and full list of victims remain limited. Further intelligence on their TTPs and victimology could enhance defensive strategies.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
ransomware
financial-motivation
business-targeting
cybercriminal

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Sep 14, 2023
Last Seen
Feb 10, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.