ALP-001 logo

ALP-001

0 incidentes 0 paises 0 sectores ransomware IQ Ultimo: -
Ver en IntelTracker → APTTrail →
ALP-001 emerged around March 2026 as a Tor-based data leak site, marking a shift for an established Initial Access Broker (IAB) from selling network access to direct extortion. The group's primary motivation is financial gain through data exfiltration and public shaming on its dedicated leak site. What distinguishes ALP-001 is its background as an IAB, with some of its data leak claims being of questionable credibility, potentially involving information from misconfigured services or publicly available sources. The group has also publicly sought ransomware partners, indicating an ability to broker access but a lack of in-house capabilities for large-scale ransomware deployment or sustained extortion operations.

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Tipo
ransomware
Pais origen
IQ
Motivacion
-
Impacto
63
Actualizado
Sat, 20 Ju

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaAustriaBelgiumBrazilCanadaSwitzerlandChinaCubaCzech Republic

Sectores objetivo (SOCRadar)

Food ManufacturingOther Information ServicesSoftware PublishersAccommodationManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationWholesale TradeData Processing Services