Motivation: Financial
Breaches organizations via drive-by downloads and the ClickFix social-engineering technique, then runs double extortion, active since around September 2024 across North America and Europe. Not a RaaS but a smaller dedicated team building its own malware; ransom notes carry a unique code and a Tor .onion contact. Subject of CISA advisory AA25-203A.
Not a RaaS: a smaller dedicated team developing its own malware. Initial access via drive-by downloads from compromised sites and the ClickFix social-engineering technique; encrypts VMs; ransom notes carry a unique code and a Tor .onion contact rather than an up-front demand. Subject of CISA advisory AA25-203A (2025).
Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →
Check your exposure privately, or request a tailored exposure audit.