noescape logo

noescape

1 incidentes 0 paises 1 sectores ransomware RU Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
NoEscape ransomware emerged in May 2023 as a Ransomware-as-a-Service (RaaS) operation, which functions by providing malicious code and infrastructure to affiliates for a share of ransom payments. It is widely understood to be a rebrand of the defunct Avaddon ransomware group, which ceased operations in 2021. Despite this, NoEscape's operators assert that their malware and infrastructure were built from scratch. The group is assessed with high confidence to be of Eastern European or Russian origin, evidenced by its policy of not targeting Commonwealth of Independent States (CIS) countries and providing free decryption keys to victims in these regions. NoEscape's primary motivation is financial gain, and it distinguishes itself by employing a triple-extortion model that includes encrypting data, exfiltrating sensitive information, and threatening Distributed Denial of Service (DDoS) attacks, in addition to listing victims on a dedicated leak site. The service offers affiliates extensive
Tecnicas MITRE
T1471, T1036, T1090, T1047, T1486, T1071.001

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

United Arab EmiratesAustriaAustraliaAzerbaijanBelgiumBurundiBermudaBrazilCanadaSwitzerland

Sectores atacados

Healthcare (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesReal EstateHospitalsEnterprises & HoldingAccommodationAir TransportationManufacturingConstruction

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com