LostTrust is a double-extortion ransomware operation that emerged in March 2023 and publicized over 50 victims within days of launching its leak site in September 2023, believed to be a rebrand of the MetaEncryptor gang, primarily targeting manufacturing, professional services, construction, and education sectors with 71% of known victims in the US. Known victims: 53
Objectives
Executive Summary
LostTrust is a double-extortion ransomware group that emerged in March 2023, rapidly targeting sectors including manufacturing, professional services, construction, and education. The group gained notoriety by publicizing over 50 victims within days of launching their leak site (September 2023) and is suspected to be a rebrand of the MetaEncryptor gang.
Goals & Targeting
LostTrust targets sectors where sensitive data and intellectual property are abundant, such as manufacturing and professional services, enabling both financial gain and organizational disruption. Their geographic focus on the US may stem from higher ransomware success rates in English-speaking regions and easier access to high-value targets.
Enhanced Description
LostTrust operates as a double-extortion ransomware group, leveraging both encrypted data and stolen information for maximum pressure on victims. The group primarily targets manufacturing, professional services, construction, and education sectors, with the majority (71%) of known victims located in the US. Emerging from March 2023, LostTrust gained significant attention by swiftly publicizing victim data after encrypting it, which is a hallmark of their double extortion tactics. The group's recent operations suggest a focus on inducing fear through rapid leak site deployment, targeting industries that may have sensitive data or are more likely to comply with extortion demands.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
LostTrust's campaigns demonstrate a rapid victim acquisition strategy, leveraging aggressive phishing and double extortion. Notable operations include the targeted attack on educational institutions, possibly exploiting开学季 vulnerabilities. The group's operational tempo suggests a decentralized approach, with a focus on high-impact targets to maximize financial gain quickly.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in LostTrust's capabilities as a ransomware group due to their rapid victimization rate and clear operational tactics. However, limited historical data prior to September 2023 may affect long-term trend analysis.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics