DataLeak is a ransomware group that first appeared in late 2022, specializing in widespread attacks against organizations to extract sensitive data. Their primary motivation is financial, achieved through double extortion tactics which combine data encryption with threats to publicly release stolen information. The group differentiates itself by maintaining a professional operational posture and demanding high ransoms. DataLeak is noted for its use of advanced encryption and obfuscation techniques to avoid detection.
Tecnicas MITRE
T1486, T1059.003, T1078.001, T1566.001, T1036.005
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.