Skira is a financially motivated ransomware group that emerged around late 2024, with its first victim publicly announced in December 2024. The group, also known by the alias SKIRA TEAM, operates with a dual extortion model, leveraging both data encryption and the threat of public exposure of exfiltrated sensitive information. Skira is characterized by its targeting of critical technology infrastructure, including VMware ESXi and Microsoft Exchange servers, to facilitate data theft and compel ransom payments through public shaming tactics on dedicated leak sites. This group distinguishes itself through its relatively small size and consistent focus on exfiltrating significant volumes of data from its victims.
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.