Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors imncrew

Description

IMN Crew is a data extortion and ransomware group that emerged in late March 2025, primarily targeting financial services organizations in the US, Croatia, and Indonesia by exploiting exposed perimeter services such as firewalls and VPNs, claiming at least five victims. Known victims: 12

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

IMN Crew is a data extortion and ransomware group targeting financial services globally. Emerging in March 2025, they exploit exposed perimeter services such as firewalls and VPNs to gain unauthorized access, encrypting systems for financial gain.

Goals & Targeting

IMN Crew's strategic objectives are centered around maximizing financial gains through ransomware deployment and data extortion. Their targeting profile focuses on sectors with high financial stakes, particularly the financial services industry, which often houses sensitive customer data and has a higher tolerance for downtime costs. The group's geographic targeting across multiple countries suggests an operational capability that transcends regional boundaries, likely reflecting their capacity to identify and exploit vulnerabilities globally. The choice of specific countries like the US, Croatia, and Indonesia may be influenced by a combination of sector vulnerability, economic value, and the ease with which perimeter services can be exploited in those regions.

Enhanced Description

IMN Crew operates with a primary focus on financial gain through data extortion and ransomware attacks. Eminating in late March 2025, the group has targeted financial institutions across multiple countries, including the US, Croatia, and Indonesia. Their modus operandi involves exploiting vulnerabilities in exposed perimeter services, such as firewalls and VPNs, to infiltrate networks, exfiltrate data, and deploy ransomware to disrupt business operations. At least five confirmed victims have been reported since their emergence, with a total of 12 known targets. IMN Crew's activities indicate a clear shift towards exploiting easily accessible attack vectors that are often left unpatched or misconfigured in financial sectors. This approach aligns with their strategic focus on high-value targets where data is sensitive and businesses are more likely to pay ransoms to avoid operational disruptions.

Key Capabilities

  • Exploiting exposed firewall and VPN vulnerabilities
  • Ransomware deployment
  • Data extortion
  • Network intrusion techniques
  • Victim identification based on sector and regional criteria

MITRE ATT&CK Tactics

Network intrusion tactics
Disruption
Financial gain

ATT&CK Techniques

T1059.003 - Malware: Component Communication (e.g., C2 communications)
T1078 - Internal Network Communications (e.g., using legitimate protocols for C2)
T1497.001 - Data Exfiltration: Web-Based Transfers
T1566.001 - Credential Access: OS Credential Dumping
T1036 - masquerade

Software / Tooling

Cobalt Strike (Potential)
Custom Exploits for Firewall/VPN vulnerabilities
Encryptive tools for ransomware deployment
Data exfiltration utilities

Campaigns & Victims

IMN Crew has demonstrated a concerted effort to exploit financial sectors globally, with campaigns characterized by their technical focus on perimeter vulnerabilities. Their operational tempo shows consistent activity from May 2025, suggesting a dedicated team with access to resources enabling multi-country operations. victims include financial institutions, highlighting the group's understanding of how to maximize extortion value. Notable past operations have resulted in significant financial losses and operational downtime for targeted organizations.

IOC Patterns

  • Phishing emails targeting financial sector employees
  • Exploits targeting firewall/VPN services
  • Ransomware-related network traffic anomalies
  • Data exfiltration attempts via web-based transfers
  • C2 communications over legitimate protocols

Recommended Actions

  • Implement strict patch management for perimeter devices (firewalls, VPNs)
  • Monitor for unusual network activity indicative of C2 communication
  • Conduct regular phishing simulations to mitigate social engineering risks
  • Enhance incident response plans with focus on ransomware indicators
  • Consider third-party services for threat intelligence sharing in the financial sector

Suggested Tags

Ransomware
Data extortion
Financial sector
Criminal activity
Network exploitation

Confidence Assessment

Moderate confidence is placed in IMN Crew's profile due to specific details about their targeting and tactics. However, the group has only been active since March 2025, and comprehensive analysis of their long-term strategies and full toolset remains limited. Further investigation into their campaign patterns and associated infrastructure could enhance understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Data extortion
Financial sector
Criminal activity
Network exploitation

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
May 5, 2025
Last Seen
Sep 16, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.