Play
Reports
59
First seen
May 13, 2025
Last seen
Aug 9, 2026
Motivation
Financial
Targeting
Sectors
Victim regions
×1×14
United States×14
Netherlands×2
Sweden×1
Andorra×1
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1021.001 Remote Services: Remote Desktop Protocol ×2T1562.001 Impair Defenses: Disable or Modify Tools ×2T1204.002 User Execution: Malicious File ×1T1560.001 Archive Collected Data: Archive via Utility ×1T1003 OS Credential Dumping ×1T1036 Masquerading ×1T1566.002 Phishing: Spearphishing Link ×1T1070.001 Indicator Removal: Clear Windows Event Logs ×1T1021.002 Remote Services: SMB/Windows Admin Shares ×1T1110 Brute Force ×1T1486 Data Encrypted for Impact ×1T1003.006 OS Credential Dumping: DCSync ×1
Indicators
domain ×60filename ×40hash_sha256 ×10hash_sha1 ×10hash_md5 ×10ip_v4 ×4url ×2registry_key ×1
Indicator values are available on Pro and via the API.
Recent reports
High