Uptime Hamster: 10d 9h 34mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Void Rabisu

Void Rabisu

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Aliases: Tropical Scorpius
Ver en IntelTracker → APTTrail →
Void Rabisu, also known by the alias Tropical Scorpius, is a cyber threat actor that emerged in 2022, initially engaged in financially motivated ransomware operations using Cuba Ransomware. The group underwent a significant transformation around October 2022, shifting its primary objectives to cyber-espionage driven by geopolitical interests, particularly targeting Ukraine and its allies. This evolution blurs the traditional lines between cybercrime and state-sponsored advanced persistent threat activity, as Void Rabisu increasingly employs techniques and targets typically associated with APT groups. The group is assessed with high confidence to operate with motivations aligned with Russian interests, though direct state sponsorship remains unconfirmed. A defining characteristic is their strategic use of the RomCom backdoor for intelligence gathering, alongside exploitation of zero-day vulnerabilities in high-profile software to achieve their espionage goals.

Aliases del actor

Tropical Scorpius

Actores similares

void-balauractor · 1Void Blizzardapt · 0Void Arachneapt · 0Void Manticoreapt · 0Void Bansheeapt · 0Void Balaurapt · 0SHADOW-VOID-042apt · 0VoidCryptransomware · 0
Motivacion