Team Underground is a ransomware group that emerged in early July 2023, initiating continuous, high-profile attacks across various industries globally. The group re-emerged with an overhauled dedicated leak site in May 2024, confirming its ongoing operations. Their primary motivation is financial gain, achieved through data encryption and a dual-extortion model where they threaten to publish stolen sensitive information if a ransom is not paid. A unique characteristic setting them apart is their peculiar practice of not altering file names or extensions after encryption, making detection challenging for victims. Additionally, the group has been noted for offering assistance in identifying and resolving system vulnerabilities to their victims.
United Arab EmiratesAustraliaBrazilCanadaChinaGermanyEgyptSpainFranceUnited Kingdom
Sectores objetivo (SOCRadar)
Construction of BuildingsOther Information ServicesHospitalsManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationOil & GasEducational ServicesWholesale Trade