icefire logo

icefire

1 incidentes 1 paises 1 sectores ransomware Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
IceFire is a ransomware group that first emerged in March 2022. Initially focusing on Windows systems, the group evolved its attack capabilities to include Linux systems by early 2023, marking a significant shift in its operational model. This adaptability allows IceFire to target a broader range of enterprise networks, particularly critical servers. The group's primary motivation is financial gain, achieved through a double extortion model where sensitive data is exfiltrated before encryption, and then threatened with public release if the ransom is not paid. IceFire distinguishes itself by strategically avoiding the encryption of critical system files to ensure the compromised system remains operational, thereby increasing the pressure on victims to comply with ransom demands. They communicate with victims via a Tor-based payment portal, providing unique credentials for interaction. IceFire aligns with "big-game hunting" ransomware families, consistently targeting large enterprises w
Tecnicas MITRE
T1059.001, T1078, T1027, T1562, T1486

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

Iran (1)

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaSwitzerlandChileChinaIran, Islamic Republic ofPakistanThailandTurkeyUnited States

Sectores atacados

Media (1)

Sectores objetivo (SOCRadar)

Other Information ServicesSoftware PublishersEnterprises & HoldingManufacturingPublic AdministrationEducational ServicesData Processing ServicesInternet PublishingEducational ServicesData Processing, Hosting, and Related Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com