Uptime Hamster: 10d 12h 17mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza ZeroSevenGroup

ZeroSevenGroup

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Ver en IntelTracker → APTTrail →
ZeroSevenGroup is a cybercriminal entity that emerged publicly in July 2024, specializing in data monetization strategies by breaching organizations and leaking or selling exfiltrated sensitive information on cybercrime forums. Initially active on platforms such as NulledTo, the group expanded its operations to BreachForums, CrackedTo, and Leakbase. While not classified as an Advanced Persistent Threat, their tactics, including supply chain targeting, align with those of sophisticated actors. There is circumstantial evidence suggesting a connection or shared resources with the Belsen Group, which appeared in January 2025, noting similar posting templates and operational styles, with both groups showing an interest in network access sales. ZeroSevenGroup's operations have been linked to Yemen-based threat actors, potentially associated with the Yemen Shield hacking group, based on password reuse patterns observed across leaked databases. The group is notable for its focus on exfiltratin
CVEs relacionadas
CVE-2022-40684
Tipo
apt
Pais origen
CN
Motivacion
-
Impacto
32
Actualizado
Sat, 17 Ma

Sectores objetivo (SOCRadar)

Public AdministrationNational Security&International AffairsAutomotive