Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors losttrust

Description

LostTrust is a double-extortion ransomware operation that emerged in March 2023 and publicized over 50 victims within days of launching its leak site in September 2023, believed to be a rebrand of the MetaEncryptor gang, primarily targeting manufacturing, professional services, construction, and education sectors with 71% of known victims in the US. Known victims: 53

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

LostTrust is a double-extortion ransomware group that emerged in March 2023, rapidly targeting sectors including manufacturing, professional services, construction, and education. The group gained notoriety by publicizing over 50 victims within days of launching their leak site (September 2023) and is suspected to be a rebrand of the MetaEncryptor gang.

Goals & Targeting

LostTrust targets sectors where sensitive data and intellectual property are abundant, such as manufacturing and professional services, enabling both financial gain and organizational disruption. Their geographic focus on the US may stem from higher ransomware success rates in English-speaking regions and easier access to high-value targets.

Enhanced Description

LostTrust operates as a double-extortion ransomware group, leveraging both encrypted data and stolen information for maximum pressure on victims. The group primarily targets manufacturing, professional services, construction, and education sectors, with the majority (71%) of known victims located in the US. Emerging from March 2023, LostTrust gained significant attention by swiftly publicizing victim data after encrypting it, which is a hallmark of their double extortion tactics. The group's recent operations suggest a focus on inducing fear through rapid leak site deployment, targeting industries that may have sensitive data or are more likely to comply with extortion demands.

Key Capabilities

  • Double extortion tactics
  • Ransomware deployment
  • Encryption of files with .LT extension
  • Victim data leak via dedicated site
  • Targeting critical infrastructure sectors

MITRE ATT&CK Tactics

Data Theft or Destruction
Impact Tactics
Encryption/Decryption

ATT&CK Techniques

T1059.003 - Adlass Network Protocol Inline LUA Execution
T1078 -ansomware
T1566.001 - Exfiltration Over Web Service Using Encrypted Communications
T1566.002 - Data Staged for Future Exfiltration
T1197 - Credential Dumping

Software / Tooling

LostTrust ransomware (variant of MetaEncryptor)
Custom encryption tools
Mimikatz for credential dumping

Campaigns & Victims

LostTrust's campaigns demonstrate a rapid victim acquisition strategy, leveraging aggressive phishing and double extortion. Notable operations include the targeted attack on educational institutions, possibly exploiting开学季 vulnerabilities. The group's operational tempo suggests a decentralized approach, with a focus on high-impact targets to maximize financial gain quickly.

IOC Patterns

  • Phishing emails with malicious links or attachments
  • Encrypted files renamed with .LT extension
  • C2 infrastructure using compromised domains and coin mixers

Recommended Actions

  • Implement robust backup solutions isolated from the network
  • Monitor for Suspicious encryption activities
  • Educate employees on phishing awareness
  • Segment critical systems to limit ransomware spread
  • Establish incident response playbooks for potential extortion events
  • Collaborate with law enforcement for tracking leak sites and threat actors

Suggested Tags

Ransomware
Double extortion
Criminal activity
Critical Infrastructure targeting

Confidence Assessment

High confidence in LostTrust's capabilities as a ransomware group due to their rapid victimization rate and clear operational tactics. However, limited historical data prior to September 2023 may affect long-term trend analysis.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Double extortion
Criminal activity
Critical Infrastructure targeting

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Sep 26, 2023
Last Seen
Sep 26, 2023
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.