Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Void Rabisu

Also known as: Tropical Scorpius

Description

Void Rabisu is an intrusion set associated with both financially motivated ransomware attacks and targeted campaigns on Ukraine and countries supporting Ukraine.

AI Analysis

· 1 week ago

Executive Summary

Void Rabisu is a financially motivated threat actor group known for ransomware attacks and targeted campaigns against Ukraine and its allies. The group has demonstrated advanced capabilities in compromising critical sectors, including energy, government, and healthcare, using both traditional and novel attack vectors.

Goals & Targeting

Void Rabisu's strategic goals appear to align with both financial motivations and geopolitical objectives. By targeting Ukraine and countries supporting it, the group likely seeks to disrupt national interests while simultaneously generating revenue through ransomware campaigns. The actor's focus on sectors such as energy, government, and healthcare indicates an intent to maximize impact by compromising critical infrastructure.

Enhanced Description

Void Rabisu, also known as Tropical Scorpius, is a cyber threat actor that has emerged as a significant concern due to its dual focus on financial gain through ransomware attacks and targeted operations against geopolitical adversaries. The group's activities highlight a strategic approach to compromising high-value targets in sectors critical to national security and economic stability. Over the years, Void Rabisu has demonstrated persistence in targeting Ukraine and countries supporting Ukraine in their ongoing conflict with Russia. This suggests a sophisticated operational strategy aimed at both disrupting adversary interests and generating revenue through cyber extortion. The group's ability to adapt its tactics makes it a particularly challenging threat to mitigate for organizations operating in targeted industries.

Key Capabilities

  • Ransomware deployment
  • Targeted campaign execution
  • Spear-phishing with malicious payloads
  • Malware-based data exfiltration
  • Command and Control (C2) infrastructure

MITRE ATT&CK Tactics

Credential Access
Discovery
Execution
Lateral Movement
Exfiltration

ATT&CK Techniques

T1057
T1566.003
T1078
T1003.004
T1059.003

Software / Tooling

Qbot banking Trojan
Cobalt Strike imitative frameworks
Custom ransomware
Phishing email toolkits

Campaigns & Victims

Void Rabisu has conducted multiple campaigns targeting energy, government, and healthcare sectors in Ukraine and its allies. The group's operations often involve spear-phishing emails with macro-laced Office documents to deliver payloads. Campaigns are typically prolonged and patient, indicating a focus on long-term strategic gains rather than rapid financial extraction. Notable operations include high-profile ransomware attacks leading to significant data breaches and operational disruptions.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Use of Qbot or similar banking Trojans
  • Malicious DLLs dropped via double-pulse SMB exploit (T1057)
  • C2 communication over HTTP/HTTPS protocols

Recommended Actions

  • Implement multi-factor authentication (MFA) for critical systems.
  • Enhance email filtering to detect and block spear-phishing attempts.
  • Monitor network traffic for signs of lateral movement and unusual patterns.
  • Conduct regular employee training on phishing awareness.
  • Encrypt backups and store them offline to prevent ransomware encryption.

Suggested Tags

APT
Ransomware
Geopolitical Espionage
Critical Infrastructure

Confidence Assessment

Moderate confidence in the overall characterization of Void Rabisu. While the group's activities are well-documented, specific technical details about its tools, tactics, and procedures remain limited. Further intelligence on TTPs, associated APT groups, and exact campaign timelines would improve situational awareness.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
Geopolitical Espionage
Critical Infrastructure

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.