Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: secpo

Description

Encrypted Extension: .vanhelsing, .vanlocker. Targets Windows Platform only Known victims: 1

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

The threat actor secp0 is a medium-sophisticated criminal group targeting Windows systems with ransomware. Identified in March 2025, secp0 encrypts files using .vanhelsing and .vanlocker extensions, seeking financial gain through ransoms.

Goals & Targeting

secp0's primary goal is financial gain through ransomware campaigns, targeting sectors with high recovery costs, including healthcare and logistics. Their focus on sensitive industries during crises suggests an aim to maximize profit by exploiting current events.

Enhanced Description

secp0 is a newly emerged threat actor exploiting the COVID-19 crisis to target healthcare organizations. They leverage tailored phishing emails with COVID-19 themes to distribute TrickBot malware, compromising network access. Exploiting sensitive data like PPE orders and vaccination records, secp0 deploys wiper恶意软件 to destroy files post-ransom deadline, creating pressure for timely payments.

Key Capabilities

  • Custom ransomware
  • Wiper恶意软件 deployment
  • Targeted phishing campaigns

Software / Tooling

TrickBot
wiper malware

Campaigns & Victims

secp0 has been active in critical sectors like healthcare, leveraging COVID-19 themed phishing to distribute TrickBot. They follow a pattern of initial compromise, network traversal, and targeted wiping if ransoms are not paid.

IOC Patterns

  • Phishing emails with COVID-19 themes
  • TrickBot malware activity

Recommended Actions

  • Enhance email filtering for themed phishing
  • Implement strong user authentication protocols

Suggested Tags

Ransomware
Healthcare

Confidence Assessment

Confidence is moderate, as secp0's tactics are common but their emergence makes full details unclear.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Mar 14, 2025
Last Seen
Apr 27, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.