Uptime Hamster: 10d 11h 12mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza bluesky

bluesky

3 incidentes 2 paises 0 sectores ransomware RU Ultimo: 2026-06-29
Aliases: Heyoka, Mongall, UNC94, bisonal, tonto, tontoteam, APT ICEFOG
Ver en IntelTracker → APTTrail →
BlueSky is a ransomware variant that emerged in June 2022, primarily focused on financial extortion. This ransomware family is believed with high confidence to be operated by threat actors of Russian origin. It is notable for its rapid encryption capabilities achieved through multithreading, a technique that bears code similarities to Conti v3 and Babuk ransomware. Unlike some other prominent ransomware groups, BlueSky has not been observed operating a public data leak site. The group uniquely assigns a user ID to each victim, generated based on system information, to track them and manage the decryption process.

Aliases del actor

HeyokaMongallUNC94bisonaltontotontoteamAPT ICEFOG

Actores similares

apt-icefogactor · 1apt-45actor · 2apt-c-27actor · 2apt-c-01actor · 2apt-c-12actor · 1apt-18actor · 1apt-1877teamactor · 1apt-27actor · 1apt-30actor · 1apt-38actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Repositoriounknowngithub.comRansom Notes: bluesky (1 notes from ThreatLabz)
DLS / onionunknownccpyeuptrlatb2piua4ukhnhi7lrxgerrcrj4p2b5uhbzqm2xgdjaqid.onionbluesky
DLS / leak siteupransomware.anggipradana.comRansomware Group: bluesky
Tecnicas MITRE
T1110, T1021, T1569, T1003, T1562, T1486
CVEs relacionadas
CVE-2023-27350
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1) Russia (1)

Paises objetivo (SOCRadar)

IndiaSaudi ArabiaUnited States

Sectores objetivo (SOCRadar)

Construction of BuildingsEnterprises & HoldingManufacturingConstructionPublic AdministrationEducational ServicesEnergy & Utilities Computer Systems Design and Related ServicesNational Security&International AffairsTelecommunications

URLs nuevas detectadas en IntelTracker

github.com ransomware.anggipradana.com

Victimas (1)

Ransom Notes: bluesky (1 notes from ThreatLabz)18 Jun 2026
Report
bluesky - Ransom NotesEste grupo de ransomware tiene 1 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de resca…