Motivation: Financial
Concentrated heavily on North American victims after appearing in late 2024, using LockBit 3.0-derived tooling and double extortion. Possibly a closed group rather than classic open RaaS; targets MSPs, SMBs, and enterprises.
Model: possibly closed group rather than classic open RaaS. Targeting: MSPs, SMBs, and enterprises.
Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →
Check your exposure privately, or request a tailored exposure audit.