Ransomware needs a way in. Stolen credentials are the cheapest one.
apt73 Ransomware Group
Ransomware group profile
Description
Eraleign is a high-profile ransomware group that specializes in advanced cyberattacks targeting large organizations for maximum financial gain. Known for their sophisticated encryption methods and double extortion tactics, they employ custom-built malware to infiltrate networks and have shifted their focus towards critical infrastructure and supply chain attacks.
Key insights
- •Utilizes rapid encryption methods and multi-stage infection chains.
- •Targets multiple sectors, especially critical infrastructure and healthcare.
- •Employs double extortion tactics by threatening to leak stolen data.
- •Gains initial access via phishing campaigns and known vulnerabilities.
- •Demonstrates a trend towards leveraging REvil's toolkit and tactics.
Threat Level & Status Breakdown
For apt73 · Based on incidents in selected period
Recent activity
Monthly attack count for apt73 in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for apt73
- eraleignews.com
- ns1.eraleignews.com
- ns2.eraleignews.com
- ns3.eraleignews.com
- ns4.eraleignews.com
- bashe4aec32kr6zbifwd5x6xgjsmhg4tbowrbx4pneqhc5mqooyifpid.onion
- basheqtvzqwz4vp6ks5lm2ocq7i6tozqgf6vjcasj4ezmsy4bkpshhyd.onion
- qcgv5tfer4f46ns6ohh72zeyyh5uavoiybypzpt3lmwk5ecyqykptgqd.onion
- wn6vonooq6fggjdgyocp7bioykmfjket7sbp47cwhgubvowwd7ws5pyd.onion
- fleqwmg7xnanypt5km2m75l72q7nlcvlp2m4sdmgjxorsn6tb3zyp3qd.onion
- basherq53eniermxovo3bkduw5qqq5bkqcml3qictfmamgvmzovykyqd.onion
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for apt73
T1486
T1486
T1490
T1490
T1562
T1562
T1040
T1040
T1071
T1071
T1078
T1078
T1059
T1059
T1021
T1021
T1021.001
T1021.001
T1547
T1547
Victims(63)
| Company | Country | Status | Discovered | |
|---|---|---|---|---|
| บริษัท เมทราไบต์ คลาวด์ จำกัด | Thailand | Claimed | about 1 month ago | |
| dgcement.com | Algeria | Claimed | about 2 months ago | |
| Vicente Trapani S.A. | Argentina | Claimed | about 2 months ago | |
| گروه توسعه کسب و کار آذرستان | Iran | Claimed | about 2 months ago | |
| Western International Group | United States | Claimed | about 2 months ago | |
| Ahmet Aydeniz Group | Turkey | Claimed | about 2 months ago | |
| Holiday Palace | Spain | Claimed | about 2 months ago | |
| Rita Võ | Austria | Claimed | about 2 months ago | |
| Flazio | Italy | Claimed | about 2 months ago | |
| PT Portal Biz Nusantara | Indonesia | Claimed | 2 months ago | |
| gov.br | Brazil | Claimed | 2 months ago | |
| Flughafen Wien AG | Austria | Claimed | 2 months ago | |
| smarty.arpinet.am | Armenia | Claimed | 3 months ago | |
| elections.mia.gov.am | Armenia | Claimed | 3 months ago | |
| Tapu ve Kadastro Genel Müdürlüğü | Turkey | Claimed | 3 months ago | |
| Minsa | Mexico | Claimed | 3 months ago | |
| TVN Media | Poland | Claimed | 3 months ago | |
| Grupo Petersen | Argentina | Claimed | 3 months ago | |
| Alkaloid | North Macedonia | Claimed | 3 months ago | |
| narit.or.th | Thailand | Claimed | 3 months ago |
Page 1 of 4
Affected countries(62)
Countries where this group has been reported to target or leak victims.