Frag is a financially motivated ransomware group that first emerged in November 2024, operating as a closed entity rather than a Ransomware-as-a-Service (RaaS) model and without engaging affiliates. The group distinguishes itself by using a modular ransomware payload tailored to target specific victim environments, with support for both Windows and Linux systems. It also uniquely avoids using countdown timers on its data leak site, contrasting with common ransomware group practices. While identified as a distinct entity, Frag has been linked to the tactics, techniques, and procedures of other ransomware groups like Akira and Fog, and some analysis suggests it is a variant of the HellCat/Morpheus and AidLocker ransomware families.
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
ArgentinaCanadaGermanySpainUnited KingdomIndiaIran, Islamic Republic ofNetherlandsSingaporeUnited States
Sectores objetivo (SOCRadar)
Construction of BuildingsFood ManufacturingOther Information ServicesCredit UnionsSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationAir Transportation