LostTrust is a financially motivated ransomware group that initiated its first attacks in March 2023, publicly launching its data leak site in September 2023. The group operates as a rebrand of MetaEncryptor and exhibits significant operational and code overlap with the SFile and Mindware ransomware families. LostTrust distinguishes itself by portraying its operators in ransom notes as former "white hat hackers" who transitioned to cybercrime due to inadequate compensation for legitimate security work, claiming their actions are a means to be paid for identifying network vulnerabilities.
Tecnicas MITRE
T1176, T1057, T1531, T1490, T1566, T1090
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Construction of BuildingsFood ManufacturingOther Information ServicesRail TransportationSoftware PublishersReal EstateAccommodationManufacturingConstructionPublic Administration