groove logo

groove

1 incidentes 1 paises 1 sectores ransomware RU Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
Groove emerged in mid-2021 as a self-proclaimed ransomware group, but its alleged operator, known as "Boriselcin," later claimed it was largely a social engineering experiment designed to manipulate media and security researchers. Presenting itself as a financially motivated entity engaged in industrial espionage, Groove encouraged a loose collective of cybercriminals and was closely linked to the Russian-language RAMP underground forum. Its activities included leaking Fortinet VPN credentials and publicly calling for cyberattacks against U.S. government interests, while advising against targeting Chinese entities. Although some researchers expressed skepticism about the "hoax" claim, noting the fluidity of cybercrime groups, Groove's operational activity remained minimal and short-lived, largely ceasing by early 2022.
Tecnicas MITRE
T1027, T1486, T1562.001, T1078.003, T1560.001, T1490
CVEs relacionadas
CVE-2020-0796, CVE-2014-6271, CVE-2002-0013

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

ArgentinaAustraliaCanadaChinaGermanyUnited KingdomIndiaItalySingaporeTaiwan, Province of China

Sectores atacados

Government (1)

Sectores objetivo (SOCRadar)

Other Information ServicesMonetary Authorities-Central BankHospitalsManufacturingPublic AdministrationInternet PublishingPublishing ServicesJustice & Safety ActivitiesChemical&Pharmaceutical ManufacturingNational Security&International Affairs

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com