Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors entropy

Description

Entropy is a ransomware first seen in 1st quarter of 2022, is being used in conjunction of Dridex infection. The ransomware uses a custom packer to pack itself which has been seen in some early dridex samples.

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Entropy is a ransomware threat actor first observed in early 2022, linked to the Dridex banking Trojan. The group uses custom packers for their malware and has targeted organizations globally for financial gain through ransom demands.

Goals & Targeting

Entropy's strategic focus is on generating direct financial profit through ransomware campaigns. The group targets organizations across multiple sectors, leveraging Dridex to gain initial access. Their victims are typically chosen based on high-value data or assets that would maximize the potential for payout during a ransom event. There is no specific sector or geographic targeting observed thus far.

Enhanced Description

Entropy ransomware emerged in 2022 as part of a sophisticated attack campaign that combinedDridex infections with ransomware deployment. This actor employs a custom packer, which was similar to early Dridex samples. The group's primary strategy involves compromising systems through infection chains involving well-known malware like Dridex, suggesting a collaborative or integrated approach to attacks. While primarily focused on financial gain, Entropy demonstrate a level of technical expertise and operational capability that places them in the medium-sophistication category among cybercriminal threat actors.

Key Capabilities

  • Ransomware deployment with custom packers
  • Use of Dridex banking Trojan in infection chains
  • sophisticated persistence mechanisms
  • Lateral movement and data exfiltration techniques
  • Spear-phishing campaigns with malicious payloads

MITRE ATT&CK Tactics

Exfiltration
Encryption
Malware Deployment

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1070.004
T1002

Software / Tooling

Dridex Trojan
Custom packer (malware)
Entropy ransomware family

Campaigns & Victims

Entropy's campaigns exhibit a clear pattern of integrating Dridex infections to facilitate ransomware deployment. The group targets organizations globally, suggesting an opportunistic approach rather than sector-specific focus. Initial infection vectors include phishing emails and malicious scripts. Notable past operations have involved high-profile victims in multiple industries, with a focus on maximizing payout potential through targeted encryption.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Script-based malware delivery
  • Dridex-related indicators of compromise (IoCs)
  • Custom packer signatures in executable files
  • Ransomware payload deployment after initial infection

Recommended Actions

  • Enhance email filtering to detect spear-phishing attempts
  • Monitor for unusual script activity and process execution
  • Implement endpoint detection solutions focusing on custom packer and Dridex-related patterns
  • Segment network access to limit lateral movement potential
  • Conduct regular training sessions on phishing awareness

Suggested Tags

APT
Ransomware
Dridex
Banking Trojan
Criminal
Financial Fraud
Custom Malware

Confidence Assessment

Confidence in the data on Entropy is moderate. While their operational tactics, particularly the use of Dridex and custom packers, are well-documented, specific details on their targeting criteria and long-term infrastructure remain limited. Further analysis of their attack patterns and受害者的地理分布would improve understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
Dridex
Banking Trojan
Criminal
Financial Fraud
Custom Malware

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.