IMN Crew is a data extortion and ransomware group that emerged in late March 2025, primarily targeting financial services organizations in the US, Croatia, and Indonesia by exploiting exposed perimeter services such as firewalls and VPNs, claiming at least five victims. Known victims: 12
Objectives
Executive Summary
IMN Crew is a data extortion and ransomware group targeting financial services globally. Emerging in March 2025, they exploit exposed perimeter services such as firewalls and VPNs to gain unauthorized access, encrypting systems for financial gain.
Goals & Targeting
IMN Crew's strategic objectives are centered around maximizing financial gains through ransomware deployment and data extortion. Their targeting profile focuses on sectors with high financial stakes, particularly the financial services industry, which often houses sensitive customer data and has a higher tolerance for downtime costs. The group's geographic targeting across multiple countries suggests an operational capability that transcends regional boundaries, likely reflecting their capacity to identify and exploit vulnerabilities globally. The choice of specific countries like the US, Croatia, and Indonesia may be influenced by a combination of sector vulnerability, economic value, and the ease with which perimeter services can be exploited in those regions.
Enhanced Description
IMN Crew operates with a primary focus on financial gain through data extortion and ransomware attacks. Eminating in late March 2025, the group has targeted financial institutions across multiple countries, including the US, Croatia, and Indonesia. Their modus operandi involves exploiting vulnerabilities in exposed perimeter services, such as firewalls and VPNs, to infiltrate networks, exfiltrate data, and deploy ransomware to disrupt business operations. At least five confirmed victims have been reported since their emergence, with a total of 12 known targets. IMN Crew's activities indicate a clear shift towards exploiting easily accessible attack vectors that are often left unpatched or misconfigured in financial sectors. This approach aligns with their strategic focus on high-value targets where data is sensitive and businesses are more likely to pay ransoms to avoid operational disruptions.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
IMN Crew has demonstrated a concerted effort to exploit financial sectors globally, with campaigns characterized by their technical focus on perimeter vulnerabilities. Their operational tempo shows consistent activity from May 2025, suggesting a dedicated team with access to resources enabling multi-country operations. victims include financial institutions, highlighting the group's understanding of how to maximize extortion value. Notable past operations have resulted in significant financial losses and operational downtime for targeted organizations.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence is placed in IMN Crew's profile due to specific details about their targeting and tactics. However, the group has only been active since March 2025, and comprehensive analysis of their long-term strategies and full toolset remains limited. Further investigation into their campaign patterns and associated infrastructure could enhance understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics