Also known as: secpo
Encrypted Extension: .vanhelsing, .vanlocker. Targets Windows Platform only Known victims: 1
Objectives
Executive Summary
The threat actor secp0 is a medium-sophisticated criminal group targeting Windows systems with ransomware. Identified in March 2025, secp0 encrypts files using .vanhelsing and .vanlocker extensions, seeking financial gain through ransoms.
Goals & Targeting
secp0's primary goal is financial gain through ransomware campaigns, targeting sectors with high recovery costs, including healthcare and logistics. Their focus on sensitive industries during crises suggests an aim to maximize profit by exploiting current events.
Enhanced Description
secp0 is a newly emerged threat actor exploiting the COVID-19 crisis to target healthcare organizations. They leverage tailored phishing emails with COVID-19 themes to distribute TrickBot malware, compromising network access. Exploiting sensitive data like PPE orders and vaccination records, secp0 deploys wiper恶意软件 to destroy files post-ransom deadline, creating pressure for timely payments.
Key Capabilities
Software / Tooling
Campaigns & Victims
secp0 has been active in critical sectors like healthcare, leveraging COVID-19 themed phishing to distribute TrickBot. They follow a pattern of initial compromise, network traversal, and targeted wiping if ransoms are not paid.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence is moderate, as secp0's tactics are common but their emergence makes full details unclear.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics