Also known as: ThreatLabz
Money Message emerged in March 2023 targeting Windows and Linux systems across banking, transportation, and professional services sectors, demanding ransoms in the millions and publishing stolen data on their blog if unpaid, with most known victims based in the US. Known victims: 29 2 ransom note(s) on file
Objectives
Executive Summary
moneymessage, also known as ThreatLabz, is a medium-sophistication criminal threat actor primarily motivated by organizational-gain and financial profit. Specializing in ransomware attacks, moneymessage has targeted sectors including banking, transportation, and professional services, particularly in the United States. Known for demanding significant ransoms and publishing stolen data on their blog if payments are not made, this group poses a substantial threat to organizations managing critical infrastructure and sensitive data.
Goals & Targeting
moneymessage targets industries where data breaches and ransomware attacks can have significant financial and reputational impacts, such as banking and professional services, while also targeting transportation for potential operational disruption. Their primary motivation is organizational-gain and financial profit, with campaigns focusing on sectors that offer high rewards. The group's geographic focus is primarily in the US, suggesting a strategic targeting of regional vulnerabilities and higher ransom-paying capabilities.
Enhanced Description
moneymessage emerged in January 2023, initially targeting Windows and Linux systems across various industries. The group's primary modus operandi involves deploying ransomware to encrypt victims' data and demanding large sums for decryption keys. Notably, moneymessage has targeted North America heavily, with most known victimsBased in the US. Their campaigns have demonstrated a focus on disrupting operations through both ransom demands and the public release of stolen information, aiming to maximize financial gain while leveraging fear of data exposure to pressure victims into paying ransoms. The group's persistence and operational capabilities highlight their intent to continue targeting high-value assets across sectors critical to national infrastructure.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
moneymessage has been involved in multiple campaigns, including those targeting Forestdale, Envision Unlimited, and Yourway Transportation. Their operational tempo suggests a steady engagement in cyberattacks over several years, indicating a well-organized group capable of sustained activity. Campaigns have historically targeted critical infrastructure and professional services firms, with the intent to disrupt operations and extort substantial ransoms.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data on moneymessage is sufficient for moderate confidence in their operational profile, with clear patterns and known victimology. However, gaps exist in specific tools used and exact MITRE techniques, which would enhance understanding of their tactics.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
5
Campaigns
0
IOCs
0
Observed Data
0
Tactics