Marketo is a cybercriminal group operating a data theft marketplace that emerged in late 2020 or early 2021, distinguishing itself by exclusively focusing on data exfiltration and extortion rather than encryption-based ransomware attacks. The group's primary motivation is financial gain, achieved by stealing sensitive data from targeted organizations and then pressuring victims to pay by offering to sell or publish the stolen information. A unique tactic involves emailing victims' competitors with sample data or contacting law enforcement to intensify pressure on the victim. Marketo claims to operate independently and against traditional ransomware gangs, stating an adherence to "moral principles" that preclude network disruption or data encryption. While they deny affiliation with ransomware, they leverage similar double extortion strategies, offering to sell data to the victim first, and if unpaid, selling it to other parties or releasing critical portions publicly.
Tecnicas MITRE
T1557.001, T1078, T1566, T1569.002
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
AustraliaCanadaIndiaItalyJapanSingaporeUnited States
Sectores objetivo (SOCRadar)
Construction of BuildingsOther Information ServicesSoftware PublishersManufacturingConstructionPublic AdministrationEducational ServicesRepair&MaintenanceSpace & DefenseEnergy & Utilities