Project Relic emerged in mid-2022 as a Golang-based ransomware targeting Windows and Linux hosts, operating with a TOR-based data leak site and using double-extortion tactics, with operators dwelling in networks for days or weeks before encrypting. Known victims: 5
Objectives
Executive Summary
Project Relic is a medium-sophistication criminal threat actor targeting both Windows and Linux systems with Golang-based ransomware. Employing double-extortion tactics via a Tor-based data leak site, they seek financial gain by encrypting data and threatening to leak it unless ransoms are paid. Their patient network-dwelling behavior poses significant risks to targeted organizations.
Goals & Targeting
Project Relic's strategic objectives revolve around generating significant financial returns through ransomware campaigns. Their targeting approach has been relatively broad so far, but they appear to focus on sectors where data sensitivity and potential for financial loss are high. Sectors like healthcare, education, and utilities may be particularly vulnerable, though more specific patterns will emerge with additional campaign analysis.
Enhanced Description
Project Relic emerged in mid-2022 as a notable ransomware operation deploying Golang-based malware across both Windows and Linux environments. The group's distinctive approach involves establishing prolonged presence within victim networks before triggering encryption, maximizing the impact of their attacks. Their use of Tor-based data leak sites for double extortion—where they threaten to release stolen data unless ransoms are paid—adds psychological pressure on victims. Project Relic primarily seeks financial gain through these operations, operating with a moderate level of sophistication and a clear focus on organizational destruction.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Project Relic's campaigns are characterized by their double-extortion model and use of a Tor-based infrastructure. They maintain a low-profile operational tempo with limited but impactful campaigns since their emergence in 2022. Known victims include diverse sectors, though specifics remain scarce.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Project Relic's details is moderate, with clear patterns emerging from their activity since November 2022. Gaps include exact TTPs and specific tools used beyond their known infrastructure.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics