Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors datacarry

Description

DataCarry is a ransomware and data-extortion operation first observed in May 2025, operating a double-extortion model with a Tor-hosted leak portal and claiming victims across insurance, healthcare, aerospace, legal, and retail sectors in at least six countries. Known victims: 16 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

DataCarry is a medium-sophistication criminal threat actor specializing in ransomware and data extortion operations. They operate a double-extortion model, leveraging Tor-based infrastructure to host leak portals and demand ransoms from victims. Targeting primarily insurance, healthcare, aerospace, legal, and retail sectors across multiple countries, DataCarry poses a significant financial risk to organizations through their disruptive activities.

Goals & Targeting

DataCarry's strategic objectives are primarily financial in nature, driven by the desire for organizational gain through ransom payments and data sales. Their targeting profile focuses on sectors with high data value and vulnerability, such as healthcare and insurance, where disruptions can have severe consequences. The group's geographic focus spans multiple countries, indicating a global reach but showing particular interest in regions where their double-extortion approach may be more effective. Typical victims include enterprises with significant data assets, inadequate security postures, or limited incident response capabilities.

Enhanced Description

DataCarry is a relatively new ransomware operation that emerged in June 2024. The group employs a double-extortion tactic where victims are threatened with both data encryption and public exposure of sensitive information if demands are not met. This approach increases the pressure on organizations to comply, making it one of their key strategies for maximizing financial gain. DataCarry's infrastructure heavily relies on Tor networks to anonymize communication channels and maintain operational security. Their target sectors include industries with significant data sensitivity and potential economic impact, such as insurance and healthcare. The group has demonstrated a certain level of targeting precision, focusing on regions where the political and economic environment may make organizations more susceptible to extortion. DataCarry's modus operandi involves initial access through phishing campaigns, followed by ransomware deployment, and subsequent data exfiltration for double-extortion purposes.

Key Capabilities

  • Double extortion via ransomware and data leak campaigns
  • Use of Tor-based communication and infrastructure
  • Sophisticated phishing tactics using malicious Office documents
  • Operation of a dedicated data leak portal for extortion purposes

MITRE ATT&CK Tactics

Disruption
Exfiltration
Data Manipulation
Impact Infrastructure

ATT&CK Techniques

T1059.003
T1486.002
T1055
T1566.001
T1566.002

Software / Tooling

Spear-phishing email campaigns with malicious Office documents
Custom ransomware
Tor-based communication channels

Campaigns & Victims

DataCarry has conducted several high-profile campaigns across multiple sectors, targeting organizations in at least six countries. Their operational rhythm appears to be steady, with a focus on maintaining persistence and lateral movement within networks to maximize data exfiltration. Notable past operations include incidents in the insurance and healthcare industries where victims were forced to pay ransoms to avoid public exposure of sensitive records. The group's use of double extortion suggests a strategic shift towards more elaborate attack planning compared to basic ransomware groups.

IOC Patterns

  • Spear-phishing emails with malicious Office document attachments
  • Ransomware deployment via remote scripts
  • Data exfiltration over encrypted channels
  • C2 communications through Tor exit nodes

Recommended Actions

  • Implement robust endpoint detection and response (EDR) solutions to identify and block malicious scripts.
  • Conduct regular training sessions for employees to detect phishing attempts and suspicious emails.
  • Monitor network traffic for unusual data exfiltration patterns indicative of double-extortion campaigns.
  • Ensure offline backups are maintained and tested regularly to mitigate ransomware impacts.
  • Use DNS filtering solutions to block access to known Tor-based portals used by DataCarry.

Suggested Tags

Ransomware
Extortion
Double Extortion
Criminal
Apt

Confidence Assessment

There is moderate confidence in the details regarding DataCarry's operational techniques and targets, as they are relatively new to the threat landscape. While their TTPs are well-documented through incident reports and IOC data, there is limited visibility into their internal structures or long-term strategic goals. Gaps exist in understanding their exact toolset beyond phishing campaigns and ransomware deployment.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

6

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Extortion
Double Extortion
Criminal
Apt

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jun 26, 2024
Last Seen
Dec 6, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.