Ransomware Intelligence

brain cipher

Ransomware group profile

22Victims
63Impact score

Description

Brain Cipher Ransomware is a financially motivated cybercriminal group known for deploying sophisticated ransomware attacks on large organizations since the early 2020s. The group employs advanced tactics such as double extortion, complete network infiltration, and data exfiltration to maximize ransom payouts. Their operations have targeted sectors including healthcare and finance, demonstrating a willingness to disrupt critical services for financial gain.

Key insights

  • Targets large organizations to maximize ransom payouts.
  • Utilizes double extortion tactics, threatening data release if ransoms are not paid.
  • Employs a modified variant of the LockBit 3.0 ransomware.
  • Engages in extensive network infiltration and data exfiltration before deployment.
  • Incorporates zero-day vulnerabilities and social engineering in their attacks.
  • Ransom demands typically range from $150,000 to $8 million, primarily paid in Monero.

Threat Level & Status Breakdown

For brain cipher · Based on incidents in selected period

4.5threat level
Aggressiveness6/ 10
Lethality2.3/ 10
Criticality5.3/ 10

Status Breakdown

Data Leaked45.5%10
Claimed40.9%9
First seenJul 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for brain cipher in the selected period

22Total attacks
5peak in Oct
2.2avg / month
↓ 1 vs first month
JulAugSepOctJanFebMarAprMayJun02468

Intelligence

IOCs, YARA/Sigma rules, and related families for brain cipher

  1. mybmtbgd7aprdnw2ekxht5qap5daam2wch25coqerrq2zdioanob34ad.onion
View full IOC feed1 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for brain cipher

Other

T1486

T1486

T1490

T1490

T1041

T1041

T1070

T1070

T1059

T1059

T1562

T1562

T1021

T1021

T1134

T1134

T1548.002

T1548.002

T1021.001

T1021.001

T1210

T1210

T1080

T1080

Victims(22)

CompanyDomainCountryIndustryStatusDiscovered
squamish.netTechnology
Data Leaked
2 days ago
sheppadviser.com.auAU AustraliaProfessional Services
Data Leaked
13 days ago
ice.org.ukGB United KingdomEducation
Data Leaked
23 days ago
bridgeway-consulting.co.ukGB United KingdomProfessional Services
Data Leaked
about 1 month ago
soundinsurance.caCA CanadaFinancial Services
Data Leaked
about 2 months ago
endeavourautomotive.co.ukGB United KingdomManufacturing
Data Leaked
about 2 months ago
Eworldmeeworldme.comAE United Arab EmiratesTechnology
Data Leaked
about 2 months ago
liteline.comUS United StatesTechnology
Data Leaked
3 months ago
westonconsulting.comUS United StatesProfessional Services
Data Leaked
3 months ago
exceldor.caCA CanadaOther
Data Leaked
3 months ago
flbgroup.comGB United KingdomProfessional Services
Unknown
4 months ago
kisnet.co.jpJP JapanTechnology
Unknown
4 months ago
nwlr.caCA CanadaTechnology
Unknown
4 months ago
fsbgroup.caCA CanadaFinancial Services
Claimed
7 months ago
semag.frFR FranceEnergy & Utilities
Claimed
7 months ago
axxia.frFR FranceManufacturing
Claimed
7 months ago
oxfordcounty.caCA CanadaGovernment & Defense
Claimed
8 months ago
cdom.orgUS United StatesEducation
Claimed
8 months ago
bmsi.orgUS United StatesHealthcare
Claimed
9 months ago
bw-lv.deDE GermanyHealthcare
Claimed
10 months ago

Page 1 of 2