Ransomware Intelligence

apt73

Ransomware group profile

55Victims
Czech RepublicSource country
65Impact score
Also Known As
Bashe
APT73
Apt 73

Description

Eraleign is a high-profile ransomware group that specializes in advanced cyberattacks targeting large organizations for maximum financial gain. Known for their sophisticated encryption methods and double extortion tactics, they employ custom-built malware to infiltrate networks and have shifted their focus towards critical infrastructure and supply chain attacks.

Key insights

  • Utilizes rapid encryption methods and multi-stage infection chains.
  • Targets multiple sectors, especially critical infrastructure and healthcare.
  • Employs double extortion tactics by threatening to leak stolen data.
  • Gains initial access via phishing campaigns and known vulnerabilities.
  • Demonstrates a trend towards leveraging REvil's toolkit and tactics.

Threat Level & Status Breakdown

For apt73 · Based on incidents in selected period

4threat level
Aggressiveness10/ 10
Lethality0/ 10
Criticality1.7/ 10

Status Breakdown

Claimed100.0%55
First seenApr 2026
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 23, 2026

Recent activity

Monthly attack count for apt73 in the selected period

55Total attacks
43peak in Apr
18.3avg / month
↓ 38 vs first month
AprMayJun015304560

Intelligence

IOCs, YARA/Sigma rules, and related families for apt73

  1. ns2.eraleignews.com
  2. basherq53eniermxovo3bkduw5qqq5bkqcml3qictfmamgvmzovykyqd.onion
  3. ns3.eraleignews.com
  4. basheqtvzqwz4vp6ks5lm2ocq7i6tozqgf6vjcasj4ezmsy4bkpshhyd.onion
  5. fleqwmg7xnanypt5km2m75l72q7nlcvlp2m4sdmgjxorsn6tb3zyp3qd.onion
  6. qcgv5tfer4f46ns6ohh72zeyyh5uavoiybypzpt3lmwk5ecyqykptgqd.onion
  7. eraleignews.com
  8. bashe4aec32kr6zbifwd5x6xgjsmhg4tbowrbx4pneqhc5mqooyifpid.onion
  9. wn6vonooq6fggjdgyocp7bioykmfjket7sbp47cwhgubvowwd7ws5pyd.onion
  10. ns4.eraleignews.com
  11. ns1.eraleignews.com
View full IOC feed11 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for apt73

Other

T1486

T1486

T1490

T1490

T1562

T1562

T1040

T1040

T1071

T1071

T1078

T1078

T1059

T1059

T1021

T1021

T1021.001

T1021.001

T1547

T1547

Victims(150)

CompanyDomainCountryIndustryStatusDiscovered
gov.brGovernment & Defense
Claimed
about 13 hours ago
kliknklik.comRetail & E-Commerce
Claimed
about 13 hours ago
kliknklik.comkliknklik.comID IndonesiaRetail & E-Commerce
Claimed
about 16 hours ago
gov.brgov.brBR BrazilGovernment & Defense
Claimed
about 16 hours ago
viennaairport.comTransportation
Claimed
about 16 hours ago
viennaairport.comviennaairport.comAT AustriaTransportation
Claimed
about 18 hours ago
smarty.arpinet.amTechnology
Claimed
21 days ago
smarty.arpinet.amsmarty.arpinet.amAM ArmeniaTechnology
Claimed
21 days ago
smarty.arpinet.amsmarty.arpinet.amAM ArmeniaTechnology
Claimed
21 days ago
elections.mia.gov.am from WOLVES OF TURANAM ArmeniaGovernment & Defense
Claimed
22 days ago
elections.mia.gov.am from WOLVES OF TURANelections.mia.gov.amAM ArmeniaGovernment & Defense
Claimed
22 days ago
elections.mia.gov.am from WOLVES OF TURANAM ArmeniaGovernment & Defense
Claimed
22 days ago
tkgm.gov.trTR TurkeyGovernment & Defense
Claimed
about 1 month ago
tkgm.gov.trtkgm.gov.trTR TurkeyGovernment & Defense
Claimed
about 1 month ago
minsa.com.mxMX MexicoManufacturing
Claimed
about 1 month ago
tkgm.gov.trtkgm.gov.trTR TurkeyGovernment & Defense
Claimed
about 1 month ago
minsa.com.mxminsa.com.mxMX MexicoManufacturing
Claimed
about 1 month ago
minsa.com.mxminsa.com.mxMX MexicoManufacturing
Claimed
about 1 month ago
tvnmedia.comPA PanamaTechnology
Claimed
about 1 month ago
tvnmedia.comtvnmedia.comPA PanamaTechnology
Claimed
about 1 month ago

Page 1 of 8