Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors valencialeaks

Also known as: Valancia, Valencia

Description

ValenciaLeaks is a data-extortion group that surfaced in August–September 2024, focused on exfiltrating large volumes of data and publishing it on a dedicated leak site, with documented victims including the City of Pleasanton, CA (283 GB exfiltrated) and pharmaceutical firm Duo Pharma Biotech. Known victims: 5

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

ValenciaLeaks, also known as Valancia or Valencia, is a medium-sophisticated criminal threat actor specializing in data extortion and ransomware attacks. Emerging in August–September 2024, the group has targeted industries such as local government and pharmaceuticals, exfiltrating large volumes of sensitive data to publish on a dedicated leak site. With notable victims including the City of Pleasanton, CA (283 GB stolen) and Duo Pharma Biotech, ValenciaLeaks poses an increasing threat to organizations seeking financial gain through ransom demands.

Goals & Targeting

ValenciaLeaks appears to target sectors where sensitive data has high commercial or reputational value. Their primary focus is on exfiltrating large volumes of data from governments, healthcare organizations, and corporate entities. The group's choice of victims reflects a strategic interest in industries that are likely to pay ransoms due to the sensitive nature of their data or the potential for reputational damage if leaked publicly. ValenciaLeaks' targeting profile suggests an emphasis on North American and European organizations, though their geographic scope may expand as they gain more resources and sophistication.

Enhanced Description

ValenciaLeaks is a relatively new but rapidly evolving cybercriminal group that has gained notoriety for its data extortion campaigns. The group primarily operates in the darknet, leveraging sophisticated techniques to infiltrate target networks, steal sensitive information, and extort payment in exchange for data integrity. ValenciaLeaks first appeared on threat intelligence radar in August–September 2024, with its initial campaign targeting municipalities and healthcare organizations. Their modus operandi involves large-scale data theft using a combination of phishing, social engineering, and credential harvesting to breach their targets' systems. Once inside, the group deploys custom or modified tools to exfiltrate massive amounts of data, which they subsequently leak on dedicated websites. The group's victims have included the City of Pleasanton, CA (283 GB stolen) and pharmaceutical firm Duo Pharma Biotech, indicating a preference for high-profile targets with significant data assets.

Key Capabilities

  • Data exfiltration via sophisticated techniques
  • Use of dedicated leak sites for extortion
  • Custom or modified tools for network infiltration
  • Spear-phishing campaigns targeting high-value sectors
  • Large-scale data theft operations

MITRE ATT&CK Tactics

Initial Access
Credential Access
Exfiltration
Impact

Campaigns & Victims

ValenciaLeaks has demonstrated a rapid operational tempo, with its first campaigns unfolding quickly in late 2024. The group's victims so far include local government and pharmaceutical sectors, indicating a preference for industries with significant data assets that are more likely to comply with their demands. Notable operations include the extraction of 283 GB from the City of Pleasanton, CA, and an attack on Duo Pharma Biotech. While the group's campaign patterns are still emerging, they appear to focus on breaching targets within a relatively short timeframe (weeks) before initiating exfiltration.

IOC Patterns

  • Use of phishing emails with malicious links as initial infection vector
  • Spear-phishing campaigns targeting government and healthcare sectors
  • C2 infrastructure using leased web hosting services
  • Patterns of network traffic indicative of data exfiltration
  • Use of darknet marketplaces or forums for communication

Recommended Actions

  • Implement advanced email filtering to detect phishing attempts
  • Monitor network traffic for anomalies associated with data exfiltration
  • Enhance MFA (Multi-Factor Authentication) for critical accounts
  • Conduct regular security audits and patch management
  • Consider dark web scanning services to identify potential breaches

Suggested Tags

ransomware
extortion
government-targeted
healthcare-targeted
data-theft

Confidence Assessment

Low confidence in ValenciaLeaks' precise toolset and TTPs beyond data exfiltration and phishing. Further sightings and analysis are required to fully characterize the group's capabilities and campaign patterns.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Healthcare Targeting
ransomware
extortion
government-targeted
healthcare-targeted
data-theft

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Sep 18, 2024
Last Seen
Sep 18, 2024
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.