TRIPLESTRENGTH
0 incidentes
0 paises
0 sectores
apt Ultimo: -
TRIPLESTRENGTH is a financially motivated cybercriminal threat actor identified by Google Threat Intelligence in early 2025. The group, comprising a small number of individuals, has been active since at least 2020, initially with ransomware-related forum activity, and its structured operations have been tracked from 2023. This actor primarily engages in a "triple threat" strategy, which involves deploying ransomware on on-premises systems, hijacking cloud accounts for illicit cryptocurrency mining, and advertising or selling initial access to compromised infrastructure on underground forums. While its origin country remains unknown, the group operates within established cybercriminal ecosystems and engages in forum-based recruitment. Its primary motivation is financial gain, setting itself apart through its diversified revenue streams that combine traditional ransomware attacks with cloud resource hijacking and initial access brokering.
Sectores objetivo (SOCRadar)
Energy & Utilities Information ServicesTelecommunicationsSoftware PublishersComputer Systems Design and Related Services