Flocker (also linked to the FSociety brand) is a ransomware-as-a-service group active since 2023–2024, targeting Windows and Linux systems via phishing, compromised RDP, and exploit kits using a double extortion model, and observed collaborating with FunkSec. Known victims: 59 1 ransom note(s) on file
Objectives
Executive Summary
Flocker, also linked to the FSociety brand, is a ransomware-as-a-service (RaaS) group identified since April 2024. The group primarily targets Windows and Linux systems through phishing, compromised RDP connections, and exploit kits, employing a double extortion model. Collaborating with FunkSec, Flocker has demonstrated medium sophistication, focusing on financial gain and organizational disruption.
Goals & Targeting
Flocker's primary objectives revolve around financial gain through ransomware operations. The group targets organizations across multiple sectors, particularly those with weaker cybersecurity measures or high data sensitivity. Their victims include healthcare, finance, and educational institutions. The choice of targets suggests a focus on maximizing impact while minimizing detection risk.
Enhanced Description
Flocker is a ransomware-as-a-service (RaaS) group emerged in late 2023–2024 and operates under the FSociety brand. The threat actor targets Windows and Linux systems using a combination of phishing campaigns, compromised Remote Desktop Protocol (RDP) access, and exploit kits. Flocker employs a double extortion model, where victims are threatened with data encryption and subsequent leakages if demands are not met. This group is notable for its collaboration with FunkSec, enhancing its operational capabilities and attack vectors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Flocker's campaign patterns include a focus on stealing sensitive data and encrypting systems, often followed by demands for cryptocurrency payments. The group has been active since April 2024, with operations observed in collaboration with FunkSec. Notable victims number 59 to date, primarily across sectors with high data value. Their operational tempo is moderate but persistent.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Flocker's details is moderate due to limited公开 documentation. While TTPs are clear, specific targeting patterns and exact toolset remain unclear. Additional intelligence gaps include precise受害者 industries and地理分布.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics