Also known as: Wine Tempest
One actor that has emerged in this trend of human-operated attacks is an active, highly adaptive group that frequently drops Wadhrama as payload. PARINACOTA impacts three to four organizations every week and appears quite resourceful: during the 18 months that we have been monitoring it, we have observed the group change tactics to match its needs and use compromised machines for various purposes, including cryptocurrency mining, sending spam emails, or proxying for other attacks. The group’s goals and payloads have shifted over time, influenced by the type of compromised infrastructure, but in recent months, they have mostly deployed the Wadhrama ransomware. The group most often employs a smash-and-grab method, whereby they attempt to infiltrate a machine in a network and proceed with subsequent ransom in less than an hour. There are outlier campaigns in which they attempt reconnaissance and lateral movement, typically when they land on a machine and network that allows them to quickly and easily move throughout the environment. PARINACOTA’s attacks typically brute forces their way into servers that have Remote Desktop Protocol (RDP) exposed to the internet, with the goal of moving laterally inside a network or performing further brute-force activities against targets outside the network. This allows the group to expand compromised infrastructure under their control. Frequently, the group targets built-in local administrator accounts or a list of common account names. In other instances, the group targets Active Directory (AD) accounts that they compromised or have prior knowledge of, such as service accounts of known vendors. The group adopted the RDP brute force technique that the older ransomware called Samas (also known as SamSam) infamously used. Other malware families like GandCrab, MegaCortext, LockerGoga, Hermes, and RobbinHood have also used this method in targeted ransomware attacks. PARINACOTA, however, has also been observed to adapt to any path of least resistance they can utilize. For instance, they sometimes discover unpatched systems and use disclosed vulnerabilities to gain initial access or elevate privileges.
Executive Summary
PARINACOTA (aka Wine Tempest) is a highly adaptive ransomware group known for its rapid, smash-and-grab tactics. Primarily deploying Wadhrama ransomware, the group frequently targets exposed RDP services and compromises servers to expand their infrastructure. Their activities include brute-force attacks, credential dumping, and lateral movement, often adapting their methods to maximize efficiency.
Goals & Targeting
PARINACOTA primarily seeks financial gain through ransomware deployment. Their targeting strategy focuses on sectors with accessible RDP services and networks that allow for quick compromise and lateral movement. The group's victims are often industries with less robust cybersecurity measures, including healthcare, education, and small-to-medium enterprises (SMEs). Their global reach suggests a broad geographic focus, though specific regions may be targeted based on infrastructure susceptibility.
Enhanced Description
PARINACOTA is a active threat actor known for its highly adaptive tactics in deploying ransomware, particularly Wadhrama. The group has been observed operating for at least 18 months, demonstrating the ability to quickly shift strategies based on the targets they compromise. Their primary method involves brute-forcing access to RDP-exposed servers, often using compromised machines for further attacks such as lateral movement, credential dumping, or deploying additional malicious activities like cryptocurrency mining. In some cases, the group conducts extended campaigns involving network reconnaissance and deeper infiltration, depending on the ease of access. The actor's adaptability is notable, as they frequently pivot to unpatched systems or known vulnerabilities to maintain their campaign effectiveness.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
PARINACOTA's campaigns demonstrate a mix of quick-strike and prolonged attack patterns. They often target machines with quick extraction of ransom, but in cases where network access is easy, they conduct deeper reconnaissance. The group has been noted for its ability to adapt to defensive measures and exploit vulnerabilities, making them a persistent threat. Their operational tempo is rapid, attempting to infiltrate multiple organizations weekly.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderately high confidence in the group's existence and primary tactics based on observed behavior and shared intelligence. Limited information is available regarding specific targeted sectors or countries, which creates some uncertainty about their precise focus.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics