Aware is a ransomware group that emerged in late 2023 and gained momentum throughout 2024. It operates a Tor-based data leak site. The group is known for deploying a specialized ransomware variant designed to encrypt sensitive data across Windows, Linux, and ESXi environments. Aware employs a double extortion model, which involves exfiltrating victim data before encryption to maintain leverage, even if victims have backups. Public documentation regarding Aware's specific victims, tools, or detailed tactics, techniques, and procedures is currently very limited.
Malware asociado
zhmimikatz
Tecnicas MITRE
T1486 - Data Encrypted for Impact, T1490 - Inhibit System Recovery, T1059.001 - Command and Scripting Interpreter, T1133 - External Remote Services
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
United Arab EmiratesAustraliaBelgiumBrazilCanadaGermanyFranceItalyMaldivesPakistan
Sectores objetivo (SOCRadar)
Energy & Utilities ConstructionManufacturingRetailTransportation&WarehousingInformation ServicesFinanceProfessional&Technical ServicesEducational ServicesHealthCare & Social Assistance