Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors raznatovic

Description

RANSOMED.VC aka Raznatovic Known victims: 5

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

The threat actor identified as 'raznatovic' is a medium-sophistication criminal group primarily motivated by organizational gain and financial objectives. Known for ransomware activities, this actor has been observed operating since December 2023 through January 2024. While details are limited, their targeting patterns suggest a focus on sectors with high financial thresholds, leveraging standard ransomware tactics.

Goals & Targeting

Raznatovic's objectives revolve around maximizing financial gains through ransomware campaigns. Their strategic focus likely targets industries where ransoms are more easily negotiable, such as healthcare, education, and municipal services. The group's victims suggest a preference for mid-sized organizations with weaker cybersecurity defenses, allowing for efficient attacks that yield higher returns.

Enhanced Description

Raznatovic is an emerging threat group primarily engaged in ransomware operations aimed at generating financial gains. The group's activities have been observed from late 2023 to early 2024, indicating a structured approach to cybercriminal operations. While specific details about their targeting sectors and countries are absent, the nature of their attacks suggests they target organizations with significant financial resources or sensitive data that could be monetized through ransom demands.

Key Capabilities

  • Ransomware deployment
  • Phishing tactics
  • Exploitation of vulnerabilities

MITRE ATT&CK Tactics

Data Destruction
Initial Access
Credential Access

ATT&CK Techniques

T1078
T1566
T1036

Software / Tooling

Ransomware
Cobalt Strike

Campaigns & Victims

Raznatovic's campaigns likely involve phishing emails, malicious links, and exploit kits to gain unauthorized access. Once inside, the group employs ransomware to encrypt critical systems, demanding payment for decryption keys. Observations suggest a preference for double extortion tactics, where both encrypted data and stolen information are used to pressure victims.

IOC Patterns

  • Spear-phishing emails
  • Malicious links leading to downloads
  • Encrypted communication channels

Recommended Actions

  • Implement multi-factor authentication
  • Conduct regular cybersecurity awareness training
  • Enhance network visibility with EDR solutions
  • Establish robust backup and recovery processes

Suggested Tags

Ransomware
Criminal activity
Financial gain

Confidence Assessment

Low confidence due to limited data. Gaps include specific targeting sectors, exact TTPs, associated tools, and confirmed campaign details. More comprehensive reporting is needed for a precise threat assessment.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Government Targeting
Ransomware
Criminal activity
Financial gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Dec 17, 2023
Last Seen
Jan 7, 2024
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.