Ransomware Intelligence

eraleign (apt73) Ransomware Group

Ransomware group profile

20Victims
Czech RepublicSource country
65Impact score
Also Known As
Bashe
APT73
Apt 73

Description

Eraleign is a high-profile ransomware group that specializes in advanced cyberattacks targeting large organizations for maximum financial gain. Known for their sophisticated encryption methods and double extortion tactics, they employ custom-built malware to infiltrate networks and have shifted their focus towards critical infrastructure and supply chain attacks.

Key insights

  • Utilizes rapid encryption methods and multi-stage infection chains.
  • Targets multiple sectors, especially critical infrastructure and healthcare.
  • Employs double extortion tactics by threatening to leak stolen data.
  • Gains initial access via phishing campaigns and known vulnerabilities.
  • Demonstrates a trend towards leveraging REvil's toolkit and tactics.

Threat Level & Status Breakdown

For eraleign (apt73) · Based on incidents in selected period

2.3threat level
Aggressiveness5/ 10
Lethality0/ 10
Criticality1.7/ 10

Status Breakdown

Claimed100.0%20
First seenMar 2026
Last seenJul 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedAug 7, 2026

Recent activity

Monthly attack count for eraleign (apt73) in the selected period

20Total attacks
6peak in Mar
4avg / month
↓ 2 vs first month
MarAprMayJunJul02468

Intelligence

IOCs, YARA/Sigma rules, and related families for eraleign (apt73)

  1. eraleignews.com
  2. ns1.eraleignews.com
  3. ns2.eraleignews.com
  4. ns3.eraleignews.com
  5. ns4.eraleignews.com
  6. bashe4aec32kr6zbifwd5x6xgjsmhg4tbowrbx4pneqhc5mqooyifpid.onion
  7. basheqtvzqwz4vp6ks5lm2ocq7i6tozqgf6vjcasj4ezmsy4bkpshhyd.onion
  8. qcgv5tfer4f46ns6ohh72zeyyh5uavoiybypzpt3lmwk5ecyqykptgqd.onion
  9. wn6vonooq6fggjdgyocp7bioykmfjket7sbp47cwhgubvowwd7ws5pyd.onion
  10. fleqwmg7xnanypt5km2m75l72q7nlcvlp2m4sdmgjxorsn6tb3zyp3qd.onion
  11. basherq53eniermxovo3bkduw5qqq5bkqcml3qictfmamgvmzovykyqd.onion
View full IOC feed11 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for eraleign (apt73)

Other

T1486

T1486

T1490

T1490

T1562

T1562

T1040

T1040

T1071

T1071

T1078

T1078

T1059

T1059

T1021

T1021

T1021.001

T1021.001

T1547

T1547

Victims(20)

ThailandTechnologymetrabyte.cloud
Claimed
15 days ago
ArgentinaProfessional Servicesvicentetrapani.com
Claimed
about 1 month ago
AustriaManufacturingritavo.com
Claimed
about 1 month ago
ItalyTechnologyflazio.com
Claimed
about 1 month ago
Claimed
about 1 month ago
TurkeyGovernment & Defensetkgm.gov.tr
Claimed
3 months ago
MexicoManufacturingminsa.com.mx
Claimed
3 months ago
ArgentinaFinancial Servicesgrupopetersen.com.ar
Claimed
3 months ago
North MacedoniaHealthcarealkaloid.com.mk
Claimed
3 months ago
United StatesProfessional Servicesjgpetrucci.com
Claimed
3 months ago
KenyaGovernment & Defenseifmis.go.ke
Claimed
4 months ago
MalaysiaEnergy & Utilitieswhessoe.com.my
Claimed
4 months ago
United StatesManufacturingphb.com
Claimed
4 months ago
SeychellesGovernment & Defenseegov.sc
Claimed
4 months ago
MoroccoTechnologyiam.ma
Claimed
4 months ago
PhilippinesGovernment & Defensedpwh.gov.ph
Claimed
5 months ago
United StatesRetail & E-Commercedoghairinc.com
Claimed
5 months ago
United Arab EmiratesGovernment & Defenseshj.ae
Claimed
5 months ago
SerbiaEducationbg.ac.rs
Claimed
5 months ago
SpainFinancial Servicesbanak.com
Claimed
5 months ago