Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ransomcartel

Description

Ransom Cartel is a ransomware-as-a-service operation that surfaced in December 2021, assessed by Palo Alto Unit 42 to share source code and technical overlap with the defunct REvil group, suggesting its operators had prior access to REvil's codebase, conducting double-extortion attacks against corporate networks.

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 weeks ago

Executive Summary

Ransom Cartel is a ransomware‑as‑a‑service (RaaS) operation that emerged in December 2021 and appears to leverage code shared with the defunct REvil group. It conducts double‑extortion attacks, encrypting victim data while exfiltrating sensitive information to pressure organizations into paying ransom for decryption and non‑disclosure.

Goals & Targeting

Ransom Cartel’s strategic objective is financial profit through ransomware extortion, amplified by double‑extortion tactics that increase leverage over victims. The group targets any organization that can generate sizable ransom payouts, with a preference for sectors that store valuable proprietary or personal data, such as healthcare, finance, manufacturing, and professional services. Geographic targeting is opportunistic, focusing on regions where law enforcement response is perceived as slower or where ransom payments are more likely. Typical victims are mid‑size to large enterprises with inadequate network segmentation, weak credential hygiene, and limited backup resilience, making them vulnerable to both encryption and data‑leak threats.

Enhanced Description

Ransom Cartel is a medium‑sophistication criminal outfit that provides ransomware capabilities to affiliates through a ransomware‑as‑a‑service model. First observed in December 2021, Unit 42 analysis indicates that the group reuses source code and tooling originally developed by the REvil (Sodinokibi) ransomware, suggesting that its operators have direct access to or have inherited REvil's development assets. The service offers affiliates a turnkey solution that includes encryption modules, data exfiltration scripts, and ransom note templates, enabling rapid deployment against corporate networks. The group’s primary attack methodology is double‑extortion: after compromising a victim’s environment, they encrypt critical files and simultaneously exfiltrate sensitive data to a leak site or dark‑web forum. This dual pressure tactic increases the likelihood of ransom payment, as victims face both operational downtime and potential data exposure. Ransom Cartel’s affiliates typically gain initial access via phishing, compromised remote desktop protocols (RDP), or exploiting unpatched vulnerabilities in publicly exposed services. Operationally, the cartel employs a modular architecture that allows affiliates to customize payloads, choose encryption algorithms, and configure C2 channels. The ransomware payloads are often delivered as PowerShell or Windows executable dropper files, which then stage additional tools such as credential‑dumpers (e.g., Mimikatz) and file‑transfer utilities (e.g., Rclone) to facilitate data theft. The group also uses bullet‑proof hosting and fast‑flux DNS techniques to obscure its command‑and‑control infrastructure. Ransom Cartel’s business model mirrors other RaaS operations: affiliates receive a share of the ransom proceeds, while the core developers retain a percentage for ongoing development and support. This model incentivizes rapid adoption and broad targeting across multiple industries, making the group a persistent threat to organizations lacking robust cyber hygiene and incident response capabilities.

Key Capabilities

  • Ransomware encryption and payload delivery
  • Data exfiltration using cloud storage and file‑transfer tools
  • Credential dumping (e.g., Mimikatz)
  • PowerShell and Windows command‑line execution
  • Persistence via scheduled tasks and registry run keys
  • Network reconnaissance and lateral movement via RDP and SMB
  • Obfuscation and anti‑analysis techniques
  • Use of bullet‑proof hosting and fast‑flux DNS for C2

MITRE ATT&CK Tactics

Impact
Credential Access
Defense Evasion
Exfiltration
Command and Control
Execution
Persistence
Discovery
Lateral Movement

ATT&CK Techniques

T1486
T1490
T1566.001
T1566.002
T1059.001
T1059.003
T1078.001
T1078.003
T1021.001
T1021.004
T1105
T1041
T1070.004
T1027
T1560.001
T1567.001

Software / Tooling

Ransom Cartel custom ransomware
Cobalt Strike (used by affiliates)
Mimikatz
PowerShell
Rclone
Custom data‑exfiltration scripts
Windows Scheduled Tasks

Campaigns & Victims

Ransom Cartel operates an affiliate‑driven campaign model, releasing new ransomware builds and updates on a regular cadence to maintain effectiveness against evolving defenses. Campaigns typically begin with phishing emails or compromised RDP credentials, followed by rapid lateral movement and credential harvesting. Once foothold is achieved, the ransomware encrypts files while simultaneously exfiltrating data to cloud storage services or dedicated leak sites. The group frequently publishes stolen data on dark‑web forums to increase pressure on victims. Operational tempo is high, with multiple concurrent attacks across diverse industries, and the group leverages bullet‑proof hosting to maintain resilient C2 infrastructure. Notable incidents attributed to Ransom Cartel include attacks on European manufacturing firms and North American healthcare providers in 2022‑2023, where ransom demands exceeded several million dollars.

IOC Patterns

  • Spear‑phishing emails with malicious Office documents or PDF attachments containing PowerShell macros
  • Compromised RDP services accessed via weak or reused passwords
  • C2 communication over HTTP/HTTPS using encrypted traffic, often routed through TOR or fast‑flux domains
  • Data staging on public cloud storage (e.g., AWS S3, Google Drive) before leak
  • Ransom notes delivered as .txt, .html, or .htm files placed in user directories
  • Use of bullet‑proof hosting and domain‑generation algorithms for C2

Recommended Actions

  • Enforce multi‑factor authentication (MFA) on all remote access services, especially RDP and VPN.
  • Implement robust email security with attachment sandboxing and anti‑phishing training.
  • Maintain regular, offline‑air‑gapped backups and test restoration procedures quarterly.
  • Apply patch management promptly, focusing on publicly exposed services and common RDP vulnerabilities.
  • Segment networks to limit lateral movement and restrict privileged account access.
  • Deploy endpoint detection and response (EDR) solutions capable of detecting ransomware behavior and credential dumping tools.
  • Monitor network traffic for anomalous outbound connections to known C2 infrastructure or high‑entropy DNS queries.
  • Establish an incident response playbook that includes double‑extortion scenarios and data leak mitigation.

Suggested Tags

ransomware
RaaS
double-extortion
criminal
financial-gain
REvil-derived
cyber‑crime

Confidence Assessment

Confidence in the core attributes of Ransom Cartel (RaaS model, REvil code reuse, double‑extortion tactics) is high, based on multiple Unit 42 analyses and observed campaign artifacts. However, gaps remain regarding specific targeted sectors, geographic focus, and the full inventory of tools used by affiliates, as public reporting is limited. Continuous monitoring of threat feeds and victim disclosures is recommended to refine these details.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.