Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors flocker

Description

Flocker (also linked to the FSociety brand) is a ransomware-as-a-service group active since 2023–2024, targeting Windows and Linux systems via phishing, compromised RDP, and exploit kits using a double extortion model, and observed collaborating with FunkSec. Known victims: 59 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Flocker, also linked to the FSociety brand, is a ransomware-as-a-service (RaaS) group identified since April 2024. The group primarily targets Windows and Linux systems through phishing, compromised RDP connections, and exploit kits, employing a double extortion model. Collaborating with FunkSec, Flocker has demonstrated medium sophistication, focusing on financial gain and organizational disruption.

Goals & Targeting

Flocker's primary objectives revolve around financial gain through ransomware operations. The group targets organizations across multiple sectors, particularly those with weaker cybersecurity measures or high data sensitivity. Their victims include healthcare, finance, and educational institutions. The choice of targets suggests a focus on maximizing impact while minimizing detection risk.

Enhanced Description

Flocker is a ransomware-as-a-service (RaaS) group emerged in late 2023–2024 and operates under the FSociety brand. The threat actor targets Windows and Linux systems using a combination of phishing campaigns, compromised Remote Desktop Protocol (RDP) access, and exploit kits. Flocker employs a double extortion model, where victims are threatened with data encryption and subsequent leakages if demands are not met. This group is notable for its collaboration with FunkSec, enhancing its operational capabilities and attack vectors.

Key Capabilities

  • Ransomware distribution via phishing campaigns
  • Exploitation using exploit kits
  • Compromised RDP access for initial breach
  • Double extortion tactics
  • Collaboration with other threat groups (e.g., FunkSec)

MITRE ATT&CK Tactics

Exfiltration
Encryption
Defense-Evasion

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Custom ransomware
Exploit kits
Phishing toolkits

Campaigns & Victims

Flocker's campaign patterns include a focus on stealing sensitive data and encrypting systems, often followed by demands for cryptocurrency payments. The group has been active since April 2024, with operations observed in collaboration with FunkSec. Notable victims number 59 to date, primarily across sectors with high data value. Their operational tempo is moderate but persistent.

IOC Patterns

  • Spear-phishing via email attachments
  • Malicious scripts execution (e.g., PowerShell)
  • C2 communications over Caddy-based platforms or custom tools
  • RDP brute-force attempts

Recommended Actions

  • Implement strict RDP access controls and multi-factor authentication.
  • Monitor for suspicious script executions in IT environments.
  • Encrypt sensitive data at rest with strong encryption standards.
  • Enhance email filtering to detect phishing campaigns.
  • Conduct regular security audits and patch management.

Suggested Tags

APT
ransomware
espionage
financial-sector

Confidence Assessment

Confidence in Flocker's details is moderate due to limited公开 documentation. While TTPs are clear, specific targeting patterns and exact toolset remain unclear. Additional intelligence gaps include precise受害者 industries and地理分布.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Phishing
APT
ransomware
espionage
financial-sector

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Apr 25, 2024
Last Seen
Jul 31, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.