freecivilian logo

freecivilian

1 incidentes 1 paises 1 sectores ransomware RU Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
FreeCivilian emerged in January 2022, initially claiming access to significant data before launching a leak website in late February 2022, coinciding with the 2022 Russian invasion of Ukraine. This group is assessed with moderate confidence to be a nation-state actor, potentially linked to Belarusian or Russian government entities such as UNC1151 or GRU, rather than an independent cybercriminal entity. Its primary motivation is disruptive and politically driven, aiming to destabilize Ukrainian government operations through data leaks and website defacements, distinguishing it from typical ransomware groups that prioritize financial gain. FreeCivilian notably attempted to monetize stolen data on dark web forums but, upon failure, released it for free, a behavior inconsistent with pure financial extortion and indicative of state-sponsored hacktivism.
Tecnicas MITRE
T1486, T1562, T1071, T1129

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

Russia (1)

Paises objetivo (SOCRadar)

ArgentinaAustraliaUkraineUnited States

Sectores atacados

Government (1)

Sectores objetivo (SOCRadar)

Other Information ServicesSoftware PublishersEnterprises & HoldingManufacturingPublic AdministrationEducational ServicesSpace & DefenseEnergy & Utilities InsuranceAircraft Manufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com