Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors rebornvc

Also known as: RansomedVC2

Description

RebornVC is a rebrand of RansomedVC re-emerging in July 2025 under new leadership, using data auctions, direct extortion, and double extortion techniques with ransom demands ranging from $10,000 to $1,000,000, with confirmed victims in the US and Brazil. Known victims: 3

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

RebornVC, a rebranded version of RansomedVC, has emerged in July 2025 under new leadership. The group specializes in ransomware attacks employing data auctions, direct extortion, and double extortion techniques. Their operations have already impacted victims in the US and Brazil, with ransom demands ranging from $10,000 to $1,000,000. This actor represents a medium-sophistication threat with a clear focus on financial gain through targeted extortion campaigns.

Goals & Targeting

RebornVC appears to target sectors and countries with significant financial value or organizational complexity, leveraging both ransomware encryption and data extortion. Their focus on US and Brazilian victims suggests an initial emphasis on high-value targets in regions with potentially less mature cybersecurity defenses or higher payoffs. The group's strategic objectives align with maximizing financial gain through targeted extortion, likely selecting victims based on their ability to pay and the sensitivity of their data.

Enhanced Description

RebornVC is a re-emerged cybercriminal group that has rebranded itself from RansomedVC in July 2025. The group operates under the primary motivation of organizational gain, leveraging ransomware attacks to extort victims both directly and through double extortion tactics. These operations include not only encrypting victim data but also threatening to auction stolen information unless a ransom is paid. The group's targeting has already shown activity in the US and Brazil, suggesting an initial focus on high-value or geographically accessible targets. RebornVC's ransom demands are significant, ranging from $10,000 to $1,000,000, indicating a clear intent to maximize financial gain through their extortion campaigns. The group's relatively short operational timeline, as of July 2025, suggests they may be refining their tactics or expanding their capabilities under new leadership.

Key Capabilities

  • Ransomware deployment
  • Data auction techniques
  • Double extortion tactics
  • Geographically targeted campaigns

MITRE ATT&CK Tactics

Persistence
Credential Access
Execution
Defense Evasion
Collection
Exfiltration
Impact

Software / Tooling

Ransomware (encrypted files)
Phishing tools (spear-phishing campaigns)

Campaigns & Victims

RebornVC has launched limited but impactful campaigns in the US and Brazil, targeting victims across industries. Their operational tempo suggests they are methodical in selecting targets and executing attacks, aiming for high-impact results rather than volume. The group's rebranding under new leadership indicates an effort to reinvent their operational model or avoid detection. Notable past operations include multiple extortion campaigns leveraging both data theft and encryption.

IOC Patterns

  • Spear-phishing emails targeting specific organizations
  • Encrypted files with ransom notes
  • Lateral movement within networks
  • Scheduled task creation for persistence

Recommended Actions

  • Implement robust email filtering to detect phishing attempts
  • Monitor for异常网络活动 indicative of extortion campaigns
  • Establish regular backups and ensure they are isolated from network access
  • Educate employees on recognizing phishing and extortion tactics

Suggested Tags

Ransomware
Extortion
Double extortion
Criminal
Financial-gain

Confidence Assessment

Confidence in the data is moderate. Key details such as specific TTPs, associated tools, and definitive targeting sectors remain unclear. The limited operational timeline and sparse IOCs contribute to gaps in understanding this actor's full capabilities and modus operandi.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Extortion
Double extortion
Criminal
Financial-gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jul 8, 2025
Last Seen
Jul 9, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.