Groove emerged in mid-2021 as a loose criminal collective linked to former Babuk gang members, known for publicly leaking Fortinet VPN credentials to attract affiliates and calling for attacks on US government and financial targets; the group later claimed its entire operation was a hoax to mislead security researchers. Known victims: 13
Objectives
Executive Summary
Groove is a criminal threat actor group linked to former members of the Babuk gang, emerging in mid-2021. Initially associated with leaking Fortinet VPN credentials and advocating attacks on US financial targets, Groove later claimed its operations were a hoax intended to mislead security researchers. This group demonstrates medium sophistication and primarily seeks organizational gain through ransomware activities.
Goals & Targeting
Groove's strategic objectives revolve around financial gain through ransomware campaigns, targeting sectors with high financial stakes such as finance and government institutions. Their targeting profile suggests a focus on countries where financial infrastructure is prominent, though specific geographic targets were not explicitly detailed in their initial activities.
Enhanced Description
Groove emerged in mid-2021 as a self-proclaimed criminal collective, drawing ties to the disbanded Babuk gang. The group gained notoriety by publicly leaking Fortinet VPN credentials, a move seemingly aimed at recruiting affiliates and attracting attention. Groove called for attacks on US government and financial institutions, aligning with its primary motivation of financial gain. However, in an unexpected twist, the group later claimed that its entire operation was fabricated as a ruse to deceive security researchers—a claim that has left uncertainty about their genuine intent and capabilities. Despite this declaration, Groove's activities have raised concerns regarding the potential manipulation of threat intelligence landscapes and the vulnerability of critical sectors to cyber threats.
MITRE ATT&CK Tactics
Campaigns & Victims
Groove's campaign patterns are characterized by attention-grabbing tactics, including credential leaks and affiliate calls for attacks. Their operational tempo was short-lived within the observed timeframe (September to October 2021), suggesting either a nascent group or potential inactivity post-hoax claim. Known victims number 13, indicating moderate targeting success, though specific details remain limited.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Groove's data is moderate due to their self-proclaimed hoax status, which complicates assessing genuine threat level. Limited specifics on TTPs and victimology leave gaps in understanding their full capabilities and targeting strategies.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
4
IOCs
0
Observed Data
0
Tactics