Entropy is a ransomware first seen in 1st quarter of 2022, is being used in conjunction of Dridex infection. The ransomware uses a custom packer to pack itself which has been seen in some early dridex samples.
Objectives
Executive Summary
Entropy is a ransomware threat actor first observed in early 2022, linked to the Dridex banking Trojan. The group uses custom packers for their malware and has targeted organizations globally for financial gain through ransom demands.
Goals & Targeting
Entropy's strategic focus is on generating direct financial profit through ransomware campaigns. The group targets organizations across multiple sectors, leveraging Dridex to gain initial access. Their victims are typically chosen based on high-value data or assets that would maximize the potential for payout during a ransom event. There is no specific sector or geographic targeting observed thus far.
Enhanced Description
Entropy ransomware emerged in 2022 as part of a sophisticated attack campaign that combinedDridex infections with ransomware deployment. This actor employs a custom packer, which was similar to early Dridex samples. The group's primary strategy involves compromising systems through infection chains involving well-known malware like Dridex, suggesting a collaborative or integrated approach to attacks. While primarily focused on financial gain, Entropy demonstrate a level of technical expertise and operational capability that places them in the medium-sophistication category among cybercriminal threat actors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Entropy's campaigns exhibit a clear pattern of integrating Dridex infections to facilitate ransomware deployment. The group targets organizations globally, suggesting an opportunistic approach rather than sector-specific focus. Initial infection vectors include phishing emails and malicious scripts. Notable past operations have involved high-profile victims in multiple industries, with a focus on maximizing payout potential through targeted encryption.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the data on Entropy is moderate. While their operational tactics, particularly the use of Dridex and custom packers, are well-documented, specific details on their targeting criteria and long-term infrastructure remain limited. Further analysis of their attack patterns and受害者的地理分布would improve understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics