XINOF (also known as Fonix/FonixCrypter) is a RaaS operation that began in June 2020 with no upfront affiliate cost and four methods of encryption per file; the operators shut down the service and released the master decryption key in January 2021, allowing free decryption for all victims.
Objectives
Executive Summary
Xinof (also known as Fonix/FonixCrypter) is a Ransomware-as-a-Service (RaaS) operation that emerged in June 2020, offering four encryption methods per file and no upfront affiliate cost. The group gained attention by shutting down their service in January 2021 and releasing the master decryption key, enabling free decryption for all victims. Despite this shutdown, Xinof poses a notable threat to organizations due to its operational model and potential re-emergence.
Goals & Targeting
Xinof's primary objective is financial gain through ransomware attacks. The group targeted organizations across various sectors, leveraging their RaaS model to extend their reach through affiliates. Despite not specifying particular sectors or countries, Xinof demonstrated a focus on maximizing revenue by allowing low-barrier entry for new affiliates to join their campaign.
Enhanced Description
Xinof is a Ransomware-as-a-Service (RaaS) operation that began in June 2020, initially offering no upfront cost for affiliates and providing four encryption methods per file. The group primarily targeted organizations seeking financial gain through ransomware activities. Xinof was notable for its customer support infrastructure, which included live chat for victims to obtain decryption keys from their operators. In January 2021, the group unexpectedly shut down operations and released the master decryption key, allowing all affected victims to decrypt files without payment. While this move garnered attention, it's unclear if Xinof has permanently ceased its activities or may re-emerge in the future with new campaigns.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Xinof's campaigns typically involved low-cost entry for affiliates, with a focus on rapid deployment and decentralized operations. The group's shutdown in January 2021 raised questions about their long-term viability but may indicate internal challenges or pressure from law enforcement. Despite this, Xinof's operational model suggests potential future campaigns if the group reorganizes.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderately High Confidence. While data on Xinof's specific TTPs and toolset is limited, the group's operational model aligns with known RaaS characteristics. The shutdown of operations and decryption key release adds context but leaves questions about future activities. Additional insights into their campaign patterns and tools would enhance confidence in this assessment.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics