Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ms13089

Also known as: ms13-089

Description

MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin, claiming a handful of victims including a law firm, operating primarily as a double-extortion actor. Known victims: 3

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

MS13089, also known as ms13-089, is a newly emerged ransomware group first observed in December 2025. The group operates primarily as a double extortion actor, targeting victims with both data encryption and exfiltration. Their activities have been limited to a few incidents, including the compromise of a law firm, suggesting an emerging threat that organizations should monitor closely.

Goals & Targeting

The strategic objectives of MS13089 appear to be driven by the pursuit of financial gain through ransom payments. Their targeting profile suggests a focus on sectors or organizations where data value is high, such as law firms, which may possess sensitive client information. The group's geographic targeting remains unclear, but their limited activity indicates they may still be developing their operational playbook.

Enhanced Description

MS13089 is a relatively new ransomware group that surfaced in December 2025. The group's name appears to be a nod to Microsoft Security Bulletin MS13-089, possibly reflecting an interest in leveraging or targeting Microsoft-related vulnerabilities or services. Operating as a double extortion actor, the group encrypts victims' data and demands ransoms for decryption keys while also threatening to release stolen information unless paid. Their primary focus has been on financial gain through ransom payments, with known victims including a law firm. The group's operational timeline is short, with activity observed between December 2025 and May 2026.

Key Capabilities

  • Ransomware deployment
  • Double extortion tactics (ransom and data exfiltration)
  • Use of anonymous communication channels for extortion demands

MITRE ATT&CK Tactics

Disruption
Exfiltration
Espionage

Campaigns & Victims

MS13089 has been linked to a limited number of campaigns, with one notable example involving the compromise of Brittany Residential. The group's short lifespan and limited victim count suggest they are either in an active development phase or undergoing operational maturation.

IOC Patterns

  • Spear-phishing emails with extortion demands
  • Use of onion-based email accounts for communication
  • Encrypted data exfiltration from targeted systems

Recommended Actions

  • Implement robust email filtering and anti-phishing solutions to detect and block suspicious messages.
  • Educate employees on recognizing phishing attempts and double extortion tactics.
  • Monitor network traffic for signs of data exfiltration or unauthorized communication channels.
  • Deploy endpoint detection and response (EDR) tools to catch ransomware activity early.
  • Regularly back up critical systems and store backups offline to mitigate the impact of ransomware attacks.

Suggested Tags

APT
ransomware
espionage
finance-sector

Confidence Assessment

The confidence level in MS13089's profile is low due to the limited data available on their campaigns, targets, and specific tactics. While their alias and operational focus provide some context, gaps remain in understanding their full capabilities, infrastructure, and long-term goals.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

1

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
ransomware
espionage
finance-sector

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Dec 18, 2025
Last Seen
May 5, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.