Ransomware Intelligence

BrainCipher

Ransomware group profile

22Victims
63Impact score

Description

Brain Cipher Ransomware is a financially motivated cybercriminal group known for deploying sophisticated ransomware attacks on large organizations since the early 2020s. The group employs advanced tactics such as double extortion, complete network infiltration, and data exfiltration to maximize ransom payouts. Their operations have targeted sectors including healthcare and finance, demonstrating a willingness to disrupt critical services for financial gain.

Key insights

  • Targets large organizations to maximize ransom payouts.
  • Utilizes double extortion tactics, threatening data release if ransoms are not paid.
  • Employs a modified variant of the LockBit 3.0 ransomware.
  • Engages in extensive network infiltration and data exfiltration before deployment.
  • Incorporates zero-day vulnerabilities and social engineering in their attacks.
  • Ransom demands typically range from $150,000 to $8 million, primarily paid in Monero.

Threat Level & Status Breakdown

For BrainCipher · Based on incidents in selected period

3threat level
Aggressiveness6/ 10
Lethality0/ 10
Criticality3/ 10

Status Breakdown

Claimed100.0%22
First seenJul 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for BrainCipher in the selected period

22Total attacks
12peak in May
3.7avg / month
↓ 1 vs first month
JulAugSepOctMayJun036912

Intelligence

IOCs, YARA/Sigma rules, and related families for BrainCipher

  1. mybmtbgd7aprdnw2ekxht5qap5daam2wch25coqerrq2zdioanob34ad.onion
View full IOC feed1 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for BrainCipher

Other

T1486

T1486

T1490

T1490

T1041

T1041

T1070

T1070

T1059

T1059

T1562

T1562

T1021

T1021

T1134

T1134

T1548.002

T1548.002

T1021.001

T1021.001

T1210

T1210

T1080

T1080

Victims(22)

CompanyDomainCountryIndustryStatusDiscovered
squamish.netsquamish.netCA CanadaTechnology
Claimed
2 days ago
sheppadviser.com.ausheppadviser.com.auAU AustraliaProfessional Services
Claimed
13 days ago
ice.org.ukice.org.ukGB United KingdomEducation
Claimed
23 days ago
flbgroup.comflbgroup.comGB United KingdomManufacturing
Claimed
about 1 month ago
kisnet.co.jpkisnet.co.jpJP JapanTechnology
Claimed
about 1 month ago
nwlr.canwlr.caCA CanadaTechnology
Claimed
about 1 month ago
liteline.comliteline.comCA CanadaManufacturing
Claimed
about 1 month ago
westonconsulting.comwestonconsulting.comUS United StatesProfessional Services
Claimed
about 1 month ago
exceldor.caexceldor.caCA CanadaOther
Claimed
about 1 month ago
soundinsurance.casoundinsurance.caCA CanadaFinancial Services
Claimed
about 1 month ago
endeavourautomotive.co.ukendeavourautomotive.co.ukGB United KingdomManufacturing
Claimed
about 1 month ago
eworldme.comeworldme.comAE United Arab EmiratesTechnology
Claimed
about 1 month ago
bridgeway-consulting.co.ukbridgeway-consulting.co.ukGB United KingdomProfessional Services
Claimed
about 1 month ago
fsbgroup.cafsbgroup.caCA CanadaFinancial Services
Claimed
7 months ago
semag.frsemag.frFR FranceTechnology
Claimed
7 months ago
axxia.fraxxia.frFR FranceTechnology
Claimed
7 months ago
oxfordcounty.caoxfordcounty.caCA CanadaGovernment & Defense
Claimed
8 months ago
cdom.orgcdom.orgUS United StatesEducation
Claimed
8 months ago
bmsi.orgbmsi.orgUS United StatesHealthcare
Claimed
9 months ago
bw-lv.debw-lv.deDE GermanyHealthcare
Claimed
10 months ago

Page 1 of 2