Toufan is a ransomware group that emerged in late 2025, operating with a clear political motivation rooted in the Israeli-Palestinian conflict. The group distinguishes itself by using cyberattacks as a form of political retribution, primarily targeting organizations perceived to be involved in actions against Gaza. Their core motivation is ideological, aiming to disrupt and expose entities linked to their declared adversaries, rather than focusing solely on financial gain, although they do demand ransoms.
Tecnicas MITRE
T1566.001, T1078, T1486, T1068
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.