Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors datakeeper

Description

DataKeeper is a ransomware-as-a-service operation dating back to at least 2018 that promoted an affiliate model called "CrystalPartnership RaaS," offering a Windows-focused ransomware toolkit with hybrid RSA-4096 encryption, open dark web registration, and an innovative split-payment mechanism to build affiliate trust.

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Datakeeper is a sophisticated ransomware-as-a-service (RaaS) operation that has been active since at least 2018. It offers a Windows-focused toolkit with hybrid encryption, utilizing an affiliate model known as 'Crystal Partnership RaaS' to distribute its operations. The group primarily seeks financial gain through ransoms and operates a split-payment mechanism to build trust within its affiliate network.

Goals & Targeting

Datakeeper's primary objectives are financial gain and organizational disruption. By leveraging affiliates under the 'Crystal Partnership RaaS' model, the group aims to maximize geographical reach and victim diversity. The targeting profile indicates a preference for organizations in industries where data loss would have significant consequences, such as healthcare and education, to ensure high ransoms.

Enhanced Description

Datakeeper is a notable ransomware-as-a-service (RaaS) operation that emerged in 2018 and has since expanded its influence by leveraging an innovative affiliate program, known as 'Crystal Partnership RaaS'. This group offers a ransomware toolkit for affiliates, utilizing hybrid RSA-4096 encryption to encrypt victim systems. The open registration on the dark web and split-payment mechanism have been key factors in Datakeeper's ability to attract and retain affiliates, fostering trust within its network. Despite its focus on financial gain, Datakeeper has demonstrated technical proficiency through its ransomware development and operational infrastructure. Its targeting patterns suggest a focus on sectors with high data value, such as healthcare and education.

Key Capabilities

  • Windows-focused ransomware toolkit
  • Hybrid RSA-4096 encryption
  • Affiliate recruitment model ('Crystal Partnership RaaS')
  • Split-payment mechanism for affiliates

Campaigns & Victims

Datakeeper has been involved in numerous ransomware campaigns targeting organizations globally, though specifics are limited due to the dark web's anonymity. Affiliates operate with relative autonomy, leading to varied tactics but consistently employing data encryption for financial gain. Past operations have focused on industries where data loss would impact business continuity and patient care, such as healthcare.

IOC Patterns

  • Spear-phishing campaigns targeting Windows users
  • Registration on dark web marketplaces
  • Use of hybrid encryption for data extortion

Recommended Actions

  • Implement employee training to recognize phishing attempts
  • Enhance network monitoring for suspicious activities related to encryption payloads
  • Conduct regular backups and ensure they are not accessible by malicious actors
  • Segment networks to limit lateral movement in case of a breach

Suggested Tags

Ransomware
Affiliate Network
Financial-Motivated
Windows Targeting
Hybrid Encryption

Confidence Assessment

The availability of data on Datakeeper's operational tactics and tools is limited, with most intelligence derived from its promotional model. There are gaps in understanding specific targeted sectors and countries outside of those noted in campaign reporting. While the group operates a sophisticated RaaS model, its reliance on third-party affiliates introduces variability in attack execution.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Affiliate Network
Financial-Motivated
Windows Targeting
Hybrid Encryption

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.