Secp0 is a ransomware group that first emerged in February 2025, known for leveraging double-extortion tactics by encrypting data and threatening public disclosure unless a ransom is paid. The group primarily targets Linux systems and ESXi environments with customized malware developed using C/C++. Their unique focus includes creating accessible data formats for their extorted information.
Key insights
•Targets Linux systems and ESXi environments with custom ELF binaries.
•Initial access often gained through compromised accounts and exploiting vulnerabilities like CVE-2023-20269.
•Employs double-extortion tactics, encrypting files and stealing sensitive information for extortion.
•Ransomware uses ChaCha20 encryption with ECDH key exchange and appends '.secp0' to encrypted files.
•Utilizes Bash one-liners for execution and deployment of the ransomware loader.
•Claims to develop software for publishing datasets in more user-friendly formats.
•Maintains persistence by abusing valid accounts to evade detection.