cheers logo

cheers

1 incidentes 1 paises 0 sectores ransomware CN Ultimo: 2026-06-25
Aliases: Cheerscrypt
Ver en IntelTracker → APTTrail →
Cheers, also known as Cheerscrypt, is a ransomware group that emerged in May 2022 with a Linux variant primarily targeting VMware ESXi servers, followed by a Windows variant in June 2022. The group is assessed with high confidence to be linked to 'Emperor Dragonfly,' a Chinese hacking group also tracked as Bronze Starlight by Secureworks and DEV-0401 by Microsoft. While operating under the guise of financially motivated ransomware, Cheerscrypt's activities are suspected to serve as a cover for Chinese government-sponsored cyber espionage campaigns. A distinguishing characteristic of Cheerscrypt is its derivation from leaked Babuk ransomware source code, but with a notable modification: it actively shuts down virtual machines using the 'esxcli' utility before proceeding with file encryption, a behavior not observed in the original Babuk ransomware. This group employs double extortion tactics, encrypting data and threatening public release of stolen information to compel ransom payments.
Tecnicas MITRE
T1486, T1490, T1071.001, T1027

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United Kingdom (1)

Paises objetivo (SOCRadar)

BelgiumUnited KingdomJapanSingaporeTurkey

Sectores objetivo (SOCRadar)

Construction of BuildingsSoftware PublishersEnterprises & HoldingManufacturingConstructionPublic AdministrationEducational ServicesInsuranceAutomotiveMining

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com