Uptime Hamster: 10d 12h 46mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Team Underground

Team Underground

0 incidentes 0 paises 0 sectores ransomware RU Ultimo: -
Aliases: Underground, TeamUnderground
Ver en IntelTracker → APTTrail →
Team Underground is a ransomware group that emerged in early July 2023, initiating continuous, high-profile attacks across various industries globally. The group re-emerged with an overhauled dedicated leak site in May 2024, confirming its ongoing operations. Their primary motivation is financial gain, achieved through data encryption and a dual-extortion model where they threaten to publish stolen sensitive information if a ransom is not paid. A unique characteristic setting them apart is their peculiar practice of not altering file names or extensions after encryption, making detection challenging for victims. Additionally, the group has been noted for offering assistance in identifying and resolving system vulnerabilities to their victims.

Aliases del actor

UndergroundTeamUnderground

Actores similares

undergroundactor · 2auditteamactor · 16malwrhunterteamactor · 11audit-teamactor · 2AuditTeamactor · 2aztroteamransomware · 2fsteamransomware · 2malekteamransomware · 2teamxxxransomware · 2apt-1877teamactor · 1
Tecnicas MITRE
T1021.002, T1059.003, T1018, T1105
CVEs relacionadas
CVE-2023-36884
Tipo
ransomware
Pais origen
RU
Motivacion
-
Impacto
78
Actualizado
Sat, 20 Ju

Paises objetivo (SOCRadar)

United Arab EmiratesAustraliaBrazilCanadaChinaGermanyEgyptSpainFranceUnited Kingdom

Sectores objetivo (SOCRadar)

Construction of BuildingsOther Information ServicesHospitalsManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationOil & GasEducational ServicesWholesale Trade