Ransomware Intelligence

BrainCipher

Ransomware group profile

27Victims
70Impact score

Description

Brain Cipher Ransomware is a financially motivated cybercriminal group known for deploying sophisticated ransomware attacks on large organizations since the early 2020s. The group employs advanced tactics such as double extortion, complete network infiltration, and data exfiltration to maximize ransom payouts. Their operations have targeted sectors including healthcare and finance, demonstrating a willingness to disrupt critical services for financial gain.

Key insights

  • Targets large organizations to maximize ransom payouts.
  • Utilizes double extortion tactics, threatening data release if ransoms are not paid.
  • Employs a modified variant of the LockBit 3.0 ransomware.
  • Engages in extensive network infiltration and data exfiltration before deployment.
  • Incorporates zero-day vulnerabilities and social engineering in their attacks.
  • Ransom demands typically range from $150,000 to $8 million, primarily paid in Monero.

Threat Level & Status Breakdown

For BrainCipher · Based on incidents in selected period

3.5threat level
Aggressiveness8/ 10
Lethality0/ 10
Criticality2.5/ 10

Status Breakdown

Claimed100.0%27
First seenJul 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 23, 2026

Recent activity

Monthly attack count for BrainCipher in the selected period

27Total attacks
12peak in May
4.5avg / month
↑ 4 vs first month
JulAugSepOctMayJun036912

Intelligence

IOCs, YARA/Sigma rules, and related families for BrainCipher

  1. 71c109f3bf4da2fc0173b9bcff07e979
  2. 9c5698924d4d1881efaf88651a304cb3
  3. 0da1f4ede654e83241eaad7719a708a0
  4. 41050b2b9f619cdd9916e3bdd5b9f2f9
  5. 8b3a45ebb7f2331e90ac57a2a20536fd
  6. 714b31629c37dee57038ca4e52ef65ac
  7. 448f1796fe8de02194b21c0715e0a5f6
  8. a0efa7fb6dff1e035510ec1f42e083e4
  9. 8dbd57b042bc63b9ecdc9e3e5506ce85
  10. 523c501118ef5d7957ce54aee86d9b1d
  11. b32a8951fc4c2e4c2d63d17200ca0032
  12. f94d17b5f232e9cfd2255ca9823cb18a
View full IOC feed20 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for BrainCipher

Other

T1486

T1486

T1490

T1490

T1041

T1041

T1070

T1070

T1059

T1059

T1562

T1562

T1021

T1021

T1134

T1134

T1548.002

T1548.002

T1021.001

T1021.001

T1210

T1210

T1080

T1080

Victims(27)

CompanyDomainCountryIndustryStatusDiscovered
eggetttax.caeggetttax.caCA CanadaOther
Claimed
3 days ago
sterlinggloballtd.comsterlinggloballtd.comGB United KingdomProfessional Services
Claimed
3 days ago
themintgaming.comthemintgaming.comUS United StatesRetail & E-Commerce
Claimed
6 days ago
alu-rex.comalu-rex.comAT AustriaManufacturing
Claimed
10 days ago
anglomoil.comanglomoil.comGB United KingdomEnergy & Utilities
Claimed
10 days ago
squamish.netsquamish.netCA CanadaTechnology
Claimed
24 days ago
sheppadviser.com.ausheppadviser.com.auAU AustraliaProfessional Services
Claimed
about 1 month ago
ice.org.ukice.org.ukGB United KingdomEducation
Claimed
about 2 months ago
flbgroup.comflbgroup.comGB United KingdomManufacturing
Claimed
about 2 months ago
kisnet.co.jpkisnet.co.jpJP JapanTechnology
Claimed
about 2 months ago
nwlr.canwlr.caCA CanadaTechnology
Claimed
about 2 months ago
liteline.comliteline.comCA CanadaManufacturing
Claimed
about 2 months ago
westonconsulting.comwestonconsulting.comUS United StatesProfessional Services
Claimed
about 2 months ago
exceldor.caexceldor.caCA CanadaOther
Claimed
about 2 months ago
soundinsurance.casoundinsurance.caCA CanadaFinancial Services
Claimed
about 2 months ago
endeavourautomotive.co.ukendeavourautomotive.co.ukGB United KingdomManufacturing
Claimed
about 2 months ago
eworldme.comeworldme.comAE United Arab EmiratesTechnology
Claimed
about 2 months ago
bridgeway-consulting.co.ukbridgeway-consulting.co.ukGB United KingdomProfessional Services
Claimed
about 2 months ago
fsbgroup.cafsbgroup.caCA CanadaFinancial Services
Claimed
8 months ago
semag.frsemag.frFR FranceTechnology
Claimed
8 months ago

Page 1 of 2