Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Pure Extraction And Ransom

Description

Pure Extraction And Ransom (PEAR) Team is the community of highly responsible and strictly disciplined members. We are a private team and have nothing common with any other threat actors. We've been monitoring this field for a long-long time. So, we understand all the processes and know well how it all works. Known victims: 81 1 negotiation log(s) available

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

The PEAR (Pure Extraction And Ransom) threat actor is a medium-sophistication criminal group primarily motivated by organizational-gain and financial objectives. Known for ransomware campaigns, PEAR has targeted various sectors through email-based attacks, leveraging negotiation tactics to maximize profits.

Goals & Targeting

PEAR operates with clear strategic objectives centered around financial gain through ransomware activities. Their targeting profile appears indiscriminate, as evidenced by their diverse list of victims across sectors such as healthcare, education, legal services, and manufacturing. This broad approach suggests that PEAR is not constrained by specific industries or geographies but focuses on vulnerabilities in various organizational settings to maximize their attack potential. The group likely selects targets based on ease of compromise, the presence of valuable data for ransom, and the ability to negotiate effectively with victims.

Enhanced Description

PEAR, or Pure Extraction And Ransom, is a cybercriminal entity operating with a focus on profit through ransomware activities. Unlike many other threat actors, PEAR emphasizes strict discipline and operates as a private, independent group without affiliations. Their operational timeline suggests sustained activity from 2023 to present, targeting a wide range of sectors and countries with no apparent bias. The group is known to communicate via encrypted channels such as onion mail services (e.g., pear@onionmail.org). PEAR's victims include various industries, reflecting a broad targeting approach. While their tactics are not extensively detailed in the public domain, their reliance on negotiation suggests an intent to maximize financial gains rather than disrupt operations.

Key Capabilities

  • Ransomware distribution
  • Email-based phishing campaigns
  • Negotiation tactics post-compromise
  • Use of encrypted communication channels

MITRE ATT&CK Tactics

Lateral Movement
Exfiltration
Ingress-Egress

ATT&CK Techniques

T1566.004

Campaigns & Victims

PEAR's campaign patterns reflect a focus on quantity over quality, targeting numerous victims without deeply embedding into particular industries. Their operational tempo indicates continuous activity across multiple sectors, suggesting a scalable and efficient approach to attacks. While specific tools are not documented, their reliance on email-based phishing aligns with many modern ransomware groups.

IOC Patterns

  • Spear-phishing emails with threats of data exfiltration or destruction
  • Use of onion-silo email domains for communication

Recommended Actions

  • Implement multi-factor authentication (MFA) for sensitive accounts
  • Monitor for异常outgoing network traffic indicative of C2 communications
  • Conduct regular employee training on phishing detection
  • Patch systems and maintain up-to-date software versions
  • Use endpoint detection and response solutions to identify potential ransomware activity

Suggested Tags

Ransomware
Email-Based Threats
Negotiation Tactics

Confidence Assessment

Confidence in PEAR's description is moderate based on available data, with gaps in specific TTPs and tools used. Additional情报would enhance understanding of their attack vectors and operational methods.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

46

Campaigns

708

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Email-Based Threats
Negotiation Tactics

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Aug 18, 2023
Last Seen
Jul 20, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.