Ransomware needs a way in. Stolen credentials are the cheapest one.
metaencryptor Ransomware Group
Ransomware group profile
Description
MetaEncryptor is a ransomware group that has gained prominence for its advanced encryption methods and targeting of high-value organizations, primarily in the healthcare sector. Known for double extortion tactics, they encrypt data and threaten to release sensitive information unless substantial ransoms are paid.
Key insights
- •Utilizes AES-256 for file encryption and RSA-2048 for key encryption.
- •Employs double extortion tactics, including data theft prior to encryption.
- •Targets primarily healthcare institutions, demanding ransoms exceeding $1 million.
- •Established aggressive use of zero-day vulnerabilities and cloud-based service targeting.
- •Employs techniques like credential harvesting and lateral movement using legitimate tools.
- •Notable for rapid evolution and rebranding, indicating a persistent operational continuity.
Threat Level & Status Breakdown
For metaencryptor · Based on incidents in selected period
Recent activity
Monthly attack count for metaencryptor in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for metaencryptor
- b834d9dbe2aed69e0b1545890f0be6f89b2a53c7
- c3804d1329b55a37bfa2f835e1e9bbc7bdb2b260f8e3627c06e02c9f52685d44
- 7eec7d07587112777016e5742c0d002d7e64a3e1fe7bde82fed8f65e3663456a
- e1c371c7c39c16d208bcbaa5b5d0714df696e6ef68b95a880673a904527c8b96
- 94f73b5dc06ba6705fcef3e759413a747049c2949a0c2e44afc03b2f9989cf73
- e06520c65bf27d9110d68ecc0de0e0824c3a99be080ead1a5b5be8fd2a26d12d
- f36dda3b97266a6a30d905c73e1f8a45c4b6681e81fb2f8f59b622de899c4421
- eae09889399fe4fb8e78b114dba0527de913d12fb1802944a88ed136e3e90577
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for metaencryptor
T1486
T1486
T1490
T1490
T1059
T1059
T1068
T1068
T1078
T1078
T1562
T1562
T1021
T1021
T1021.001
T1021.001
T1547
T1547
T1035
T1035
T1046
T1046
T1033
T1033
Victims(15)
| Company | Country | Status | Discovered | |
|---|---|---|---|---|
| Beckman Coulter Diagnostics | United States | Claimed | 3 days ago | |
| AECOM | United States | Claimed | 3 days ago | |
| ProMantra | United States | Claimed | 3 days ago | |
| Nippon Steel Corporation | Japan | Claimed | 5 days ago | |
| EllisDon | Canada | Claimed | 13 days ago | |
| SIFCO Industries INC. | United States | Claimed | 13 days ago | |
| ST Engineering | Singapore | Claimed | 13 days ago | |
| Hologic | United States | Claimed | 13 days ago | |
| Woodlore International Inc. | Canada | Claimed | 28 days ago | |
| Trailer Transit Inc | United States | Claimed | 28 days ago | |
| Weber Water Resources | United States | Claimed | 28 days ago | |
| MPA Pharma GmbH | Germany | Claimed | 28 days ago | |
| Aquamar Inc | United States | Claimed | 28 days ago | |
| 株式会社コロナ | Japan | Claimed | 28 days ago | |
| Factory Five Racing | United States | Claimed | 28 days ago |
Affected countries(22)
Countries where this group has been reported to target or leak victims.