Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Meow emerged in 2022 (resurfacing aggressively in 2024), initially operating as a RaaS using the Conti v2 codebase before transitioning to a data-extortion-only model — selling stolen data rather than encrypting files — with a heavy focus on US healthcare and medical research organizations. Known victims: 145

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Meow is a medium-sophistication criminal threat actor that has evolved from offering Ransomware as a Service (RaaS) using the Conti v2 codebase to focusing on data extortion, targeting primarily US healthcare and medical research organizations. Their operational period spans from 2022 with recent aggressive activity in 2024, shifting strategies to avoid file encryption and instead monetize stolen data.

Goals & Targeting

Meow targets US healthcare and medical research organizations due to their access to sensitive and valuable data. Healthcare sector victimology aligns with the goal of extracting high-value information for sale on dark web markets, leveraging the sector's often limited cybersecurity defenses and reliance on sensitive data systems.

Enhanced Description

Meow emerged in 2022, initially operating as a Ransomware as a Service (RaaS) group using the Conti v2 codebase. They shifted theirmodus operandito focus solely on data extortion, selling stolen data without encrypting files, targeting sensitive sectors like US healthcare and medical research organizations. This strategic change likely reflects an adaptation to avoid detection or mitigate risks associated with ransomware operations. Their primary motivation is financial gain, achieved through the monetization of stolen data.

Key Capabilities

  • Data extortion capabilities
  • Ransomware development and distribution
  • Stolen data monetization expertise
  • Targeted attacks on healthcare organizations

MITRE ATT&CK Tactics

Exfiltration of Data
Credential Access

Software / Tooling

Conti v2 ransomware
Data exfiltration tools

Campaigns & Victims

Meow has conducted numerous campaigns targeting healthcare and medical research organizations. Their campaign patterns include data theft with a focus on financial gain through selling stolen information. Notable operations include significant breaches in the US healthcare sector, demonstrating their ability to persistently target this vertical.

IOC Patterns

  • Data exfiltration activities
  • Lateral movement within networks
  • Phishing emails targeting healthcare workers

Recommended Actions

  • Enhance email filtering to detect and block phishing attempts.
  • Monitor network traffic for signs of data exfiltration.
  • Implement strict access controls on sensitive data repositories.
  • Conduct regular cybersecurity awareness training, particularly for healthcare staff.

Suggested Tags

APT
ransomware
espionage
healthcare-sector

Confidence Assessment

Confidence in the information about Meow is medium, based on reported campaigns and known tactics. Gaps include specific TTPs and exact tools used beyond initial descriptions.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Data Exfiltration
APT
ransomware
espionage
healthcare-sector

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Sep 4, 2023
Last Seen
Nov 19, 2024
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.