Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors PARINACOTA

Also known as: Wine Tempest

Description

One actor that has emerged in this trend of human-operated attacks is an active, highly adaptive group that frequently drops Wadhrama as payload. PARINACOTA impacts three to four organizations every week and appears quite resourceful: during the 18 months that we have been monitoring it, we have observed the group change tactics to match its needs and use compromised machines for various purposes, including cryptocurrency mining, sending spam emails, or proxying for other attacks. The group’s goals and payloads have shifted over time, influenced by the type of compromised infrastructure, but in recent months, they have mostly deployed the Wadhrama ransomware. The group most often employs a smash-and-grab method, whereby they attempt to infiltrate a machine in a network and proceed with subsequent ransom in less than an hour. There are outlier campaigns in which they attempt reconnaissance and lateral movement, typically when they land on a machine and network that allows them to quickly and easily move throughout the environment. PARINACOTA’s attacks typically brute forces their way into servers that have Remote Desktop Protocol (RDP) exposed to the internet, with the goal of moving laterally inside a network or performing further brute-force activities against targets outside the network. This allows the group to expand compromised infrastructure under their control. Frequently, the group targets built-in local administrator accounts or a list of common account names. In other instances, the group targets Active Directory (AD) accounts that they compromised or have prior knowledge of, such as service accounts of known vendors. The group adopted the RDP brute force technique that the older ransomware called Samas (also known as SamSam) infamously used. Other malware families like GandCrab, MegaCortext, LockerGoga, Hermes, and RobbinHood have also used this method in targeted ransomware attacks. PARINACOTA, however, has also been observed to adapt to any path of least resistance they can utilize. For instance, they sometimes discover unpatched systems and use disclosed vulnerabilities to gain initial access or elevate privileges.

AI Analysis

· 1 week ago

Executive Summary

PARINACOTA (aka Wine Tempest) is a highly adaptive ransomware group known for its rapid, smash-and-grab tactics. Primarily deploying Wadhrama ransomware, the group frequently targets exposed RDP services and compromises servers to expand their infrastructure. Their activities include brute-force attacks, credential dumping, and lateral movement, often adapting their methods to maximize efficiency.

Goals & Targeting

PARINACOTA primarily seeks financial gain through ransomware deployment. Their targeting strategy focuses on sectors with accessible RDP services and networks that allow for quick compromise and lateral movement. The group's victims are often industries with less robust cybersecurity measures, including healthcare, education, and small-to-medium enterprises (SMEs). Their global reach suggests a broad geographic focus, though specific regions may be targeted based on infrastructure susceptibility.

Enhanced Description

PARINACOTA is a active threat actor known for its highly adaptive tactics in deploying ransomware, particularly Wadhrama. The group has been observed operating for at least 18 months, demonstrating the ability to quickly shift strategies based on the targets they compromise. Their primary method involves brute-forcing access to RDP-exposed servers, often using compromised machines for further attacks such as lateral movement, credential dumping, or deploying additional malicious activities like cryptocurrency mining. In some cases, the group conducts extended campaigns involving network reconnaissance and deeper infiltration, depending on the ease of access. The actor's adaptability is notable, as they frequently pivot to unpatched systems or known vulnerabilities to maintain their campaign effectiveness.

Key Capabilities

  • RDP brute-force attacks
  • Credential dumping via mimikatz-like techniques
  • Lateral movement within networks
  • Quick ransomware deployment
  • Adaptation to system vulnerabilities

MITRE ATT&CK Tactics

Initial Access
Execution
Lateral Movement

ATT&CK Techniques

T1071.002
T1053
T1021.001

Software / Tooling

Wadhrama Ransomware
Custom RDP brute-force tools
Mimikatz (or similar credential dumping tools)

Campaigns & Victims

PARINACOTA's campaigns demonstrate a mix of quick-strike and prolonged attack patterns. They often target machines with quick extraction of ransom, but in cases where network access is easy, they conduct deeper reconnaissance. The group has been noted for its ability to adapt to defensive measures and exploit vulnerabilities, making them a persistent threat. Their operational tempo is rapid, attempting to infiltrate multiple organizations weekly.

IOC Patterns

  • RDP brute-force login attempts
  • Presence of Wadhrama ransomware files
  • Unusual network traffic originating from compromised servers
  • Credential dumping attempts in logs

Recommended Actions

  • Enhance RDP security protocols (e.g., multi-factor authentication, limiting access)
  • Monitor for brute-force login attempts on RDP services
  • Implement robust patch management practices to mitigate known vulnerabilities
  • Conduct regular audits of exposed network assets and services
  • Educate users on identifying phishing attempts and suspicious activities

Suggested Tags

Ransomware
Human-Operated
Smash-and-Grab
Cyber Crime

Confidence Assessment

Moderately high confidence in the group's existence and primary tactics based on observed behavior and shared intelligence. Limited information is available regarding specific targeted sectors or countries, which creates some uncertainty about their precise focus.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
Financial Targeting
Critical Infrastructure
Human-Operated
Smash-and-Grab
Cyber Crime

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.