Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors OldGremlin

Description

OldGremlin is a Russian-speaking ransomware group that has been active for several years. They primarily target organizations in Russia, including banks, logistics, industrial, insurance, retail, and IT companies. OldGremlin is known for using phishing emails as an initial infection vector and has developed custom malware for both Windows and Linux systems. They have conducted multiple malicious email campaigns and demand large ransoms from their victims, with some reaching millions of dollars.

AI Analysis

· 1 week ago

Executive Summary

OldGremlin is a Russian-speaking ransomware group targeting organizations in Russia across multiple sectors, including banking and logistics. They employ phishing emails as an infection vector and use custom malware for both Windows and Linux systems, demanding large ransoms from victims.

Goals & Targeting

OldGremlin's targeting strategy appears to be driven by both financial gain and disruption of critical Russian sectors. By focusing on high-value targets within these sectors, the group aims to maximize the impact of its attacks and secure substantial ransom payments. The choice of victims reflects a strategic focus on industries where business interruption would have significant economic consequences.

Enhanced Description

OldGremlin, a financially motivated cyber threat group, has been operational for several years. Primarily targeting Russian organizations in sectors such as banking, logistics, industrial manufacturing, insurance, retail, and IT, the group is known to deploy custom ransomware. Their modus operandi involves phishing campaigns that deliver malware to compromise systems. Once inside, OldGremlin encrypts data and demands large ransoms, with some incidents reported to involve payments exceeding millions of dollars. The group's focus on Russian entities suggests a strategic approach aimed at disrupting local industries while maximizing financial gain through their ransomware activities.

Key Capabilities

  • Custom ransomware deployment
  • Phishing email campaigns
  • Cross-platform malware targeting Windows and Linux systems
  • Encrypted communication channels for command and control
  • Large-scale ransom demands

MITRE ATT&CK Tactics

Credential Access
Execution
Persistence
Impact
Defense Evasion

ATT&CK Techniques

T1566.003
T1078
T1486

Software / Tooling

Custom Ransomware Binary
Phishing Email Tools

Campaigns & Victims

OldGremlin has demonstrated a consistent campaign pattern over several years, focusing on Russian entities with high financial and operational value. Their campaigns often exhibit a slow-burn approach, allowing time to infect multiple targets before deploying ransomware. Despite their primary focus on Russia, the group may pose a potential threat to international organizations with Russian business ties or employees.

IOC Patterns

  • Phishing emails targeting Russian-speaking individuals
  • Presence of custom ransomware binaries in compromised systems
  • Encrypted files indicating ransomware encryption patterns
  • Network traffic anomalies consistent with command-and-control communications

Recommended Actions

  • Implement robust email filtering to detect phishing attempts.
  • Monitor IT infrastructure for signs of unauthorized access and data encryption.
  • Deploy endpoint detection and response (EDR) solutions to identify malicious activity.
  • Conduct regular user training on phishing awareness.
  • Establish incident response plans tailored to ransomware attacks.
  • Perform regular backups of critical systems to mitigate data loss.

Suggested Tags

Ransomware
Criminal Activity
Financial Crime
Russian Speaker
Industrial Targeting

Confidence Assessment

Confidence level in OldGremlin's profile is medium. Known details about their operations, targets, and methods are accurate but limited in precision. Gaps include exact TTPs, the full range of tools used, and the extent of their international reach beyond Russia.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Phishing
Criminal Activity
Financial Crime
Russian Speaker
Industrial Targeting

Details

Type
Unknown
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.