Ransomware needs a way in. Stolen credentials are the cheapest one.
wallstreet Ransomware Group
Ransomware group profile
Description
Wallstreet is a nascent cyber extortion and ransomware group that emerged in early 2026, focusing on financial gain through data theft and extortion. They utilize double-extortion tactics, targeting various sectors with sensitive data breaches to pressure victims into compliance. Their primary operations are conducted via a Tor-based data leak site.
Key insights
- •Gains access through compromised credentials and remote-access services like VPN and RDP.
- •Utilizes exfiltration tactics to steal sensitive corporate and personal data before public exposure.
- •Employs direct extortion, threatening to leak stolen data unless ransom is paid.
- •Targets organizations in healthcare, municipal law enforcement, manufacturing, and automotive sectors.
- •Operates internationally, with notable activity in the United States and Ecuador.
Threat Level & Status Breakdown
For wallstreet · Based on incidents in selected period
Status Breakdown
Recent activity
Monthly attack count for wallstreet in the selected period
No intelligence data for this group.
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for wallstreet
T1562.001
Disable or Modify Tools
T1070.001
Clear Windows Event Logs
T1083
File and Directory Discovery
T1486
Data Encrypted for Impact
T1490
Inhibit System Recovery
T1021.001
Remote Desktop Protocol
T1080
Taint Shared Content
T1039
Data from Network Shared Drive
T1133
T1133
T1048
T1048
T1567
T1567
T1078
Valid Accounts
Affected countries(13)
Countries where this group has been reported to target or leak victims.