Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors zerotolerance

Description

ZeroTolerance is a low-profile ransomware group tracked on monitoring platforms with no detailed threat actor profiles, technical analysis, or named victim reports published by major threat intelligence vendors. Known victims: 1

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 months ago

Executive Summary

The ZeroTolerance actor is a medium-sophistication criminal group primarily motivated by organizational gain, with goals focused on ransomware and financial gain. First seen in May 2024, the group has a low profile with limited publicly available information. Their activities have been tracked, but detailed threat actor profiles and technical analyses are not published by major threat intelligence vendors.

Goals & Targeting

The strategic objectives of ZeroTolerance appear to be centered around achieving organizational gain through ransomware attacks, with a focus on generating financial benefits. The group's targeting profile is not well-defined, but it is likely that they seek to compromise organizations with valuable data or those that are more likely to pay ransom demands. Typical victims of ZeroTolerance may include small to medium-sized businesses or organizations with limited cybersecurity resources, making them more susceptible to ransomware attacks.

Enhanced Description

ZeroTolerance is a criminal ransomware group that has been tracked by monitoring platforms since May 2024. Despite their low profile, the group has managed to compromise at least one victim. The lack of detailed threat actor profiles, technical analyses, or named victim reports from major threat intelligence vendors suggests that ZeroTolerance operates under the radar, potentially using evasive tactics to avoid detection. The limited information available on this group highlights the need for continuous monitoring and threat intelligence gathering to better understand their capabilities and intentions.

Key Capabilities

  • Ransomware deployment
  • Network exploitation
  • Data encryption
  • Evasion techniques

MITRE ATT&CK Tactics

Initial Access
Execution
Privilege Escalation

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Custom RAT
Ransomware variants

Campaigns & Victims

ZeroTolerance's campaign patterns are not well understood due to the limited information available. However, it is likely that the group operates with a relatively low operational tempo, focusing on targeted attacks against specific organizations. Notable past operations are not documented, but the group's use of ransomware suggests that they may be involved in extortion-based campaigns.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux

Recommended Actions

  • Implement robust email security controls
  • Regularly update and patch software
  • Conduct regular backups and ensure data availability

Suggested Tags

Ransomware
Criminal
Financial gain

Confidence Assessment

The confidence level in the available data on ZeroTolerance is low due to the limited information available. The primary information gap exists in the group's targeting profile, technical capabilities, and campaign patterns, which are not well understood. Additional threat intelligence gathering and monitoring are necessary to better understand the capabilities and intentions of ZeroTolerance.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Criminal
Financial gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
May 5, 2024
Last Seen
May 5, 2024
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.