Ransom Cartel is a ransomware-as-a-service (RaaS) operation that first emerged around December 2021. The group's activities gained significant attention due to its highly aggressive double extortion tactics, which include not only encrypting data and threatening to publish stolen information on a leak site, but also threatening to send sensitive data to victims' partners, competitors, and news outlets to maximize reputational damage. Ransom Cartel exhibits notable code similarities and technical overlaps with the REvil ransomware, leading to speculation that its operators had access to earlier REvil source code after REvil's disappearance. While the group shares characteristics with other ransomware groups, its specific and aggressive public shaming strategy helps distinguish it. The operation was reportedly founded by Maksim Silnikau, a Belarusian-Ukrainian national.
Tecnicas MITRE
T1071.001, T1059.001, T1047, T1105, T1566.002
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
CanadaGermanyFranceUnited KingdomItalyUnited States
Sectores objetivo (SOCRadar)
Energy & Utilities ConstructionManufacturingWholesale TradeFinanceProfessional&Technical ServicesEducational ServicesHealthCare & Social AssistancePublic AdministrationOil & Gas