OnePercent Group is a cybercriminal operation active since at least November 2020 that targeted US organizations using phishing with IcedID trojans, Cobalt Strike, and double-extortion, threatening a "one percent leak" of data before escalating to a full dump or sale to REvil; the FBI issued a formal flash advisory in August 2021.
Objectives
Executive Summary
The OnePercent Group is a medium-sophistication cybercriminal operation that has been active since at least November 2020, primarily targeting US organizations for ransomware and financial gain. They utilize phishing with IcedID trojans, Cobalt Strike, and double-extortion tactics, threatening to leak sensitive data. The group's activities have prompted a formal FBI flash advisory in August 2021.
Goals & Targeting
The OnePercent Group's strategic objectives are centered on achieving financial gain through ransomware and extortion. They target US organizations, likely due to the perceived high-value of the data and systems they possess. The group's typical victims are likely to be organizations with sensitive data and a strong incentive to pay to prevent its release, such as those in the finance, healthcare, and technology sectors. By targeting these sectors, the group aims to maximize their potential financial returns while minimizing the risks associated with their operations.
Enhanced Description
The impact of the OnePercent Group's activities should not be underestimated. Their operations have significant implications for the security and integrity of targeted organizations, as well as the broader cyber threat landscape. The group's ability to successfully execute phishing campaigns and deploy sophisticated tools like Cobalt Strike underscores the ongoing challenge of defending against cyber threats. Furthermore, the group's double-extortion tactics highlight the need for organizations to prioritize both preventive measures and incident response planning to mitigate the potential consequences of a cyber attack.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The OnePercent Group's campaign patterns typically involve an initial phishing campaign to gain access to a target organization's network. Once inside, they deploy tools like IcedID and Cobalt Strike to establish persistence and move laterally within the network. The group's operational tempo is characterized by a high volume of phishing attempts, followed by a selective approach to extortion, where they carefully choose which victims to target with double-extortion tactics. Notable past operations include a wave of attacks against US organizations in 2020 and 2021, which prompted a formal FBI flash advisory in August 2021.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data on the OnePercent Group is moderate, based on publicly available information and reports from trusted sources. However, there are some information gaps, particularly regarding the group's organizational structure, leadership, and full scope of their operations. Further research and intelligence gathering are necessary to fully understand the threat posed by this group and to develop effective countermeasures.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics