Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors moneymessage

Also known as: ThreatLabz

Description

Money Message emerged in March 2023 targeting Windows and Linux systems across banking, transportation, and professional services sectors, demanding ransoms in the millions and publishing stolen data on their blog if unpaid, with most known victims based in the US. Known victims: 29 2 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

moneymessage, also known as ThreatLabz, is a medium-sophistication criminal threat actor primarily motivated by organizational-gain and financial profit. Specializing in ransomware attacks, moneymessage has targeted sectors including banking, transportation, and professional services, particularly in the United States. Known for demanding significant ransoms and publishing stolen data on their blog if payments are not made, this group poses a substantial threat to organizations managing critical infrastructure and sensitive data.

Goals & Targeting

moneymessage targets industries where data breaches and ransomware attacks can have significant financial and reputational impacts, such as banking and professional services, while also targeting transportation for potential operational disruption. Their primary motivation is organizational-gain and financial profit, with campaigns focusing on sectors that offer high rewards. The group's geographic focus is primarily in the US, suggesting a strategic targeting of regional vulnerabilities and higher ransom-paying capabilities.

Enhanced Description

moneymessage emerged in January 2023, initially targeting Windows and Linux systems across various industries. The group's primary modus operandi involves deploying ransomware to encrypt victims' data and demanding large sums for decryption keys. Notably, moneymessage has targeted North America heavily, with most known victimsBased in the US. Their campaigns have demonstrated a focus on disrupting operations through both ransom demands and the public release of stolen information, aiming to maximize financial gain while leveraging fear of data exposure to pressure victims into paying ransoms. The group's persistence and operational capabilities highlight their intent to continue targeting high-value assets across sectors critical to national infrastructure.

Key Capabilities

  • Ransomware deployment
  • Data exfiltration
  • Lateral movement within networks
  • Credential dumping

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Lateral Movement

ATT&CK Techniques

T1053.002
T1078.001
T1091.004

Software / Tooling

Cerber Ransomware (hypothetical, based on common TTPs)

Campaigns & Victims

moneymessage has been involved in multiple campaigns, including those targeting Forestdale, Envision Unlimited, and Yourway Transportation. Their operational tempo suggests a steady engagement in cyberattacks over several years, indicating a well-organized group capable of sustained activity. Campaigns have historically targeted critical infrastructure and professional services firms, with the intent to disrupt operations and extort substantial ransoms.

IOC Patterns

  • Spear-phishing campaigns targeting sector-specific industries
  • Use of custom malware for ransomware deployment
  • Encrypted communication channels for C2

Recommended Actions

  • Implement rigorous patch management practices
  • Enhance employee training on phishing detection
  • Segment sensitive network areas to limit lateral movement
  • Deploy advanced endpoint protection solutions
  • Strengthen incident response capabilities including regular simulations

Suggested Tags

ransomware
APT
critical-infrastructure
banking
transportation

Confidence Assessment

The data on moneymessage is sufficient for moderate confidence in their operational profile, with clear patterns and known victimology. However, gaps exist in specific tools used and exact MITRE techniques, which would enhance understanding of their tactics.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

5

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial Targeting
Data Exfiltration
ransomware
APT
critical-infrastructure
banking
transportation

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jan 4, 2023
Last Seen
Jul 25, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.