Motivation: Financial
Best known for mass exploitation of managed file transfer products, including the 2023 MOVEit Transfer campaign exploiting CVE-2023-34362. A mature extortion group associated in public reporting with the TA505 and FIN11-linked ecosystems.
Signature: mass zero-day exploitation and data theft. Targeting: enterprise supply chains.
Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →
Check your exposure privately, or request a tailored exposure audit.