Also known as: Tropical Scorpius
Void Rabisu is an intrusion set associated with both financially motivated ransomware attacks and targeted campaigns on Ukraine and countries supporting Ukraine.
Executive Summary
Void Rabisu is a financially motivated threat actor group known for ransomware attacks and targeted campaigns against Ukraine and its allies. The group has demonstrated advanced capabilities in compromising critical sectors, including energy, government, and healthcare, using both traditional and novel attack vectors.
Goals & Targeting
Void Rabisu's strategic goals appear to align with both financial motivations and geopolitical objectives. By targeting Ukraine and countries supporting it, the group likely seeks to disrupt national interests while simultaneously generating revenue through ransomware campaigns. The actor's focus on sectors such as energy, government, and healthcare indicates an intent to maximize impact by compromising critical infrastructure.
Enhanced Description
Void Rabisu, also known as Tropical Scorpius, is a cyber threat actor that has emerged as a significant concern due to its dual focus on financial gain through ransomware attacks and targeted operations against geopolitical adversaries. The group's activities highlight a strategic approach to compromising high-value targets in sectors critical to national security and economic stability. Over the years, Void Rabisu has demonstrated persistence in targeting Ukraine and countries supporting Ukraine in their ongoing conflict with Russia. This suggests a sophisticated operational strategy aimed at both disrupting adversary interests and generating revenue through cyber extortion. The group's ability to adapt its tactics makes it a particularly challenging threat to mitigate for organizations operating in targeted industries.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Void Rabisu has conducted multiple campaigns targeting energy, government, and healthcare sectors in Ukraine and its allies. The group's operations often involve spear-phishing emails with macro-laced Office documents to deliver payloads. Campaigns are typically prolonged and patient, indicating a focus on long-term strategic gains rather than rapid financial extraction. Notable operations include high-profile ransomware attacks leading to significant data breaches and operational disruptions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the overall characterization of Void Rabisu. While the group's activities are well-documented, specific technical details about its tools, tactics, and procedures remain limited. Further intelligence on TTPs, associated APT groups, and exact campaign timelines would improve situational awareness.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics