Eraleign, also known as APT73, is a ransomware group that surfaced in December 2023 and is primarily recognized for its deceptive tactics rather than actual ransomware deployment. The group specializes in fabricating data breach narratives and repurposing existing leaked data, often from older breaches, which they then present on a Tor-hosted leak site to create a facade of credibility. This approach distinguishes them from groups that actively encrypt systems. Eraleign later rebranded to Bashe in October 2024. They mimic the data leak site structures of established ransomware operations like LockBit and self-designate as an 'Advanced Persistent Threat' (APT) to attract affiliates and bolster their reputation for financial gain.
United Arab EmiratesArmeniaArgentinaAustraliaBangladeshBelgiumBulgariaBrazilCanadaSwitzerland
Sectores objetivo (SOCRadar)
Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateHospitalsAccommodationAir TransportationManufacturingConstruction