Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Tengu is a RaaS operation first observed in October 2025, following a double-extortion model and using Living Off The Land Binaries (LOLBins) to blend malicious activity with normal admin traffic, primarily targeting consumer goods, real estate, automotive, healthcare, and IT sectors. Known victims: 49 3 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Tengu is a recently emerged Ransomware-as-a-Service (RaaS) operation utilizing a double-extortion model and Living Off The Land Binaries (LOLBins). Targeting multiple sectors including consumer goods and healthcare, Tengu poses a significant risk to organizations due to its sophisticated tactics and rapid campaign activity.

Goals & Targeting

Tengu's primary goals are financial gain via ransoms and reputational damage through data leaks. The targeting of sectors with high data sensitivity indicates an intent to maximize both ransom demands and the impact of leaked information, affecting a diverse range of industries and potentially global operations.

Enhanced Description

Tengu emerged in October 2025 as a RaaS operator employing a double-extortion ransomware model. This approach combines data encryption with threats of leakages, enhancing the pressure on victims to comply. The use of LOLBins allows Tengu's activities to mimic legitimate administrative tasks, making detection challenging. Targeting sectors such as healthcare and real estate suggests an emphasis on industries holding sensitive or valuable data. Despite being a medium-sophistication threat actor, Tengu demonstrates effective operational methods through its campaigns.

Key Capabilities

  • Ransomware-as-a-Service (RaaS) operation
  • Double extortion tactics
  • Use of Living Off The Land Binaries (LOLBins)
  • Persistence and lateral movement techniques

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1059.003
T1070.001
T1048
T1003

Software / Tooling

Encryptoback (example)
Legitimate system tools used maliciously

Campaigns & Victims

Tengu has executed campaigns against diverse targets, including Sileno Companies Inc and Eos Technology srl. With 49 recorded victims, Tengu demonstrates an aggressive approach likely facilitated by affiliates or partners. The group's operational tempo is brisk, with activity tracked from October 2025 to March 2026, indicating both persistence and adaptability.

IOC Patterns

  • Use of legitimate binaries for malicious activities
  • Spear-phishing emails preceding infection vectors
  • Lateral movement using system administrative tools

Recommended Actions

  • Implement robust endpoint detection solutions
  • Regularly back up systems and secure backups offline
  • Monitor for unusual admin tool activity
  • Educate users on phishing awareness
  • Maintain updated security protocols and patches

Suggested Tags

Ransomware
Financial-Motivation
Double-Extortion
Healthcare-Sector
Criminal

Confidence Assessment

High confidence based on campaign data and known TTPs. Gaps include detailed TTP specifics, targeted countries beyond linked campaigns, and exact toolset used by the actor.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

4

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Financial-Motivation
Double-Extortion
Healthcare-Sector
Criminal

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Oct 23, 2025
Last Seen
Mar 7, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.