Uptime Hamster: 11d 13h 46mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza atomsilo

atomsilo

4 incidentes 1 paises 2 sectores ransomware CN Ultimo: 2026-06-29
Aliases: Atom Silo
Ver en IntelTracker → APTTrail →
AtomSilo is a ransomware group that first emerged in September 2021 and was initially observed to cease operations by year-end 2021, only to reemerge with activity reported in February 2026. The group operates with a double extortion model, primarily driven by financial gain, where they encrypt victim data and threaten to leak exfiltrated sensitive information. AtomSilo is assessed with high confidence to be linked to the Chinese state-sponsored actor BRONZE STARLIGHT, also known as Cinnamon Tempest, DEV-0401, Emperor Dragonfly, and SLIME34. This attribution suggests that its ransomware activities may serve as a smokescreen for espionage-driven data theft, distinguishing it from purely financially motivated groups. The group is notable for its rapid exploitation of recently disclosed vulnerabilities for initial access and its close operational and structural resemblances to the LockFile ransomware.

Aliases del actor

Atom Silo

Actores similares

Blackatomapt · 0

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Repositoriounknowngithub.comRansom Notes: atomsilo (1 notes from ThreatLabz)
DLS / leak siteupransomware.anggipradana.comRansomware Group: atomsilo
Malware asociado
PlugX, HUI Loader, PlugX, Pandora, PlugX, PlugX
Tecnicas MITRE
T1078.002, T1484, T1567.002, T1059.006, T1090, T1080
Victimas
2
TTPs unicas
1
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

TTPs observadas

T1566 Phishing

Paises afectados

United States (2)

Paises objetivo (SOCRadar)

American SamoaAustriaAustraliaBelgiumBrazilCanadaSwitzerlandChinaCzech RepublicGermany

Sectores atacados

Software (1) Financial Services (1)

Sectores objetivo (SOCRadar)

Other Information ServicesSoftware PublishersReal EstateManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationEducational ServicesWholesale TradeSpace & Defense

URLs nuevas detectadas en IntelTracker

github.com ransomware.anggipradana.com

Victimas (2)

Ransom Notes: atomsilo (1 notes from ThreatLabz)18 Jun 2026
Report
atomsilo - Ransom NotesEste grupo de ransomware tiene 1 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de resc…
A large bank in Asia24 Feb 2026
Ransomware United States Financial Services
Resumen A large bank in Asia ha sido afectada por un ataque de ransomware atribuido al grupo atomsilo. Este incidente representa una amenaza significa…