MadCat emerged as a ransomware group around October 2023, distinguished by its unique operational model which involved its members initially engaging in scamming other cybercriminals through the fake sale of stolen passport details on dark web forums. The group was publicly announced in November 2023, though its operational lifespan as a ransomware entity was notably brief due to prompt exposure of its fraudulent activities. Its primary motivation is financial exploitation, leveraging both direct ransomware deployment and an unusual tactic of defrauding other illicit actors. This dual approach sets MadCat apart from typical ransomware operations, with investigations linking key figures behind the ransomware to dark web accounts notorious for these scamming endeavors.
Tecnicas MITRE
T1059.001, T1071.001, T1048.002, T1486, T1562.001
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
United Arab EmiratesAlbaniaAngolaArgentinaAustriaAustraliaAzerbaijanBosnia and HerzegovinaBangladeshBelgium
Sectores objetivo (SOCRadar)
Construction of BuildingsFood ManufacturingSoftware PublishersTransit and Ground Passenger TransportationReal EstateHospitalsTransportation Equipment ManufacturingEnterprises & HoldingAccommodationAir Transportation