Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors onepercent

Description

OnePercent Group is a cybercriminal operation active since at least November 2020 that targeted US organizations using phishing with IcedID trojans, Cobalt Strike, and double-extortion, threatening a "one percent leak" of data before escalating to a full dump or sale to REvil; the FBI issued a formal flash advisory in August 2021.

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 months ago

Executive Summary

The OnePercent Group is a medium-sophistication cybercriminal operation that has been active since at least November 2020, primarily targeting US organizations for ransomware and financial gain. They utilize phishing with IcedID trojans, Cobalt Strike, and double-extortion tactics, threatening to leak sensitive data. The group's activities have prompted a formal FBI flash advisory in August 2021.

Goals & Targeting

The OnePercent Group's strategic objectives are centered on achieving financial gain through ransomware and extortion. They target US organizations, likely due to the perceived high-value of the data and systems they possess. The group's typical victims are likely to be organizations with sensitive data and a strong incentive to pay to prevent its release, such as those in the finance, healthcare, and technology sectors. By targeting these sectors, the group aims to maximize their potential financial returns while minimizing the risks associated with their operations.

Enhanced Description

The impact of the OnePercent Group's activities should not be underestimated. Their operations have significant implications for the security and integrity of targeted organizations, as well as the broader cyber threat landscape. The group's ability to successfully execute phishing campaigns and deploy sophisticated tools like Cobalt Strike underscores the ongoing challenge of defending against cyber threats. Furthermore, the group's double-extortion tactics highlight the need for organizations to prioritize both preventive measures and incident response planning to mitigate the potential consequences of a cyber attack.

Key Capabilities

  • Phishing campaign execution
  • IcedID trojan deployment
  • Cobalt Strike usage
  • Double-extortion tactics
  • Data exfiltration and leak threats

MITRE ATT&CK Tactics

Initial Access
Execution
Persistance

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

IcedID
Cobalt Strike
Custom RAT

Campaigns & Victims

The OnePercent Group's campaign patterns typically involve an initial phishing campaign to gain access to a target organization's network. Once inside, they deploy tools like IcedID and Cobalt Strike to establish persistence and move laterally within the network. The group's operational tempo is characterized by a high volume of phishing attempts, followed by a selective approach to extortion, where they carefully choose which victims to target with double-extortion tactics. Notable past operations include a wave of attacks against US organizations in 2020 and 2021, which prompted a formal FBI flash advisory in August 2021.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting

Recommended Actions

  • Implement robust email security measures to prevent phishing attacks
  • Conduct regular network monitoring for signs of IcedID and Cobalt Strike activity
  • Develop an incident response plan for ransomware and extortion attacks
  • Provide employee training on phishing and cyber security best practices

Suggested Tags

Criminal
Ransomware
Extortion
Cybercrime

Confidence Assessment

The confidence level in the available data on the OnePercent Group is moderate, based on publicly available information and reports from trusted sources. However, there are some information gaps, particularly regarding the group's organizational structure, leadership, and full scope of their operations. Further research and intelligence gathering are necessary to fully understand the threat posed by this group and to develop effective countermeasures.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Phishing

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.