Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors desolator

Description

Desolator is a ransomware group that emerged in May 2025, targeting construction and engineering firms in Latin America and Europe and technology companies in Asia, actively recruiting pen testers, initial access brokers, and social engineers via dark web forums to build an affiliate program. Known victims: 4

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Desolator is a medium-sophistication ransomware group that emerged in August 2025. They primarily target construction, engineering firms in Latin America and Europe, and technology companies in Asia. Their operations include recruiting affiliates from dark web forums to expand their attack capabilities.

Goals & Targeting

Desolator's strategic objectives are centered around financial gain through ransomware activities. They target sectors with potentially higher vulnerabilities or weaker security postures, such as construction and engineering firms in Latin America and Europe, as well as technology companies in Asia. Their targeting strategy implies a focus on regions where they may find easier entry points or less sophisticated defenses, allowing them to maximize their attack success rate.

Enhanced Description

Desolator operates as a criminal threat group with a focus on organizational gain through ransomware activities and financial profit. This group emerged in May 2025 and has been observed targeting specific sectors across multiple regions. Their use of an affiliate program, recruiting individuals such as penetration testers, initial access brokers, and social engineers from dark web forums, indicates a strategic approach to expanding their operational capabilities. While Desolator is relatively new, their quick recruitment efforts suggest potential scalability in their attack campaigns.

Key Capabilities

  • Ransomware deployment
  • Affiliate recruitment through dark web forums
  • Coordination with initial access brokers
  • Social engineering campaigns

MITRE ATT&CK Tactics

Credential Access
Execution
Discovery

ATT&CK Techniques

T1059
T1078
T1566

Software / Tooling

Phishing Campaigns using malicious links
Cobalt Strike-like tools for lateral movement
Exploit Kits for initial access

Campaigns & Victims

Desolator's campaigns have started recently, with limited known victims as of now. Their operational tempo is likely to increase as their affiliate program grows. They target specific sectors and regions, indicating a strategic focus on industries that may offer higher financial returns.

IOC Patterns

  • Encrypted files with .desolator extensions
  • Phishing emails with malicious attachments or links
  • C2 traffic via domains associated with targeted regions

Recommended Actions

  • Enhance email security to detect phishing attempts
  • Monitor network traffic for unusual activities
  • Implement regular data backups
  • Use decoy systems (honeypots) to detect malicious activity

Suggested Tags

Ransomware
Criminal
affiliate program

Confidence Assessment

Moderate confidence in Desolator's existence and basic TTPs, given their recent emergence. Limited data on specific tools used or exact TTPs remains a gap.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Criminal
affiliate program

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Aug 27, 2025
Last Seen
Aug 31, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.