Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors projectrelic

Description

Project Relic emerged in mid-2022 as a Golang-based ransomware targeting Windows and Linux hosts, operating with a TOR-based data leak site and using double-extortion tactics, with operators dwelling in networks for days or weeks before encrypting. Known victims: 5

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Project Relic is a medium-sophistication criminal threat actor targeting both Windows and Linux systems with Golang-based ransomware. Employing double-extortion tactics via a Tor-based data leak site, they seek financial gain by encrypting data and threatening to leak it unless ransoms are paid. Their patient network-dwelling behavior poses significant risks to targeted organizations.

Goals & Targeting

Project Relic's strategic objectives revolve around generating significant financial returns through ransomware campaigns. Their targeting approach has been relatively broad so far, but they appear to focus on sectors where data sensitivity and potential for financial loss are high. Sectors like healthcare, education, and utilities may be particularly vulnerable, though more specific patterns will emerge with additional campaign analysis.

Enhanced Description

Project Relic emerged in mid-2022 as a notable ransomware operation deploying Golang-based malware across both Windows and Linux environments. The group's distinctive approach involves establishing prolonged presence within victim networks before triggering encryption, maximizing the impact of their attacks. Their use of Tor-based data leak sites for double extortion—where they threaten to release stolen data unless ransoms are paid—adds psychological pressure on victims. Project Relic primarily seeks financial gain through these operations, operating with a moderate level of sophistication and a clear focus on organizational destruction.

Key Capabilities

  • Golang-based ransomware development
  • Double extortion tactics
  • Tor-based data leak site operation
  • Network dwelling for prolonged periods before encryption

MITRE ATT&CK Tactics

Exfiltration
Defense Evasion
Lateral Movement
Credential Access

ATT&CK Techniques

T1036
T1566.003
T1021
T1078

Software / Tooling

Custom Golang ransomware
Mimikatz-like tools for credential dumping

Campaigns & Victims

Project Relic's campaigns are characterized by their double-extortion model and use of a Tor-based infrastructure. They maintain a low-profile operational tempo with limited but impactful campaigns since their emergence in 2022. Known victims include diverse sectors, though specifics remain scarce.

IOC Patterns

  • Presence of Golang binaries associated with ransomware activity
  • Tor network traffic related to data leak sites
  • Encryption of files using specific cipher patterns
  • Ransom notes left in encrypted directories

Recommended Actions

  • Enhance network monitoring for suspicious Golang-based activity
  • Secure RDP access to prevent brute-force attacks
  • Implement robust backup solutions with air-gapped storage
  • Monitor for and block Tor exits nodes linked to known threat actors
  • Conduct regular employee training on phishing and extortion threats

Suggested Tags

Ransomware
Financial-Crime
Double-Extortion
Cross-platform
Network-Persistence

Confidence Assessment

Confidence in Project Relic's details is moderate, with clear patterns emerging from their activity since November 2022. Gaps include exact TTPs and specific tools used beyond their known infrastructure.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Financial-Crime
Double-Extortion
Cross-platform
Network-Persistence

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Nov 11, 2022
Last Seen
Dec 18, 2022
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.