Uptime Hamster: 10d 18h 34mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza frag

frag

2 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-29
Aliases: FELIXROOT, incluyendo el desarrollo, distribución de herramientas maliciosas
Ver en IntelTracker → APTTrail →
Frag is a financially motivated ransomware group that first emerged in November 2024, operating as a closed entity rather than a Ransomware-as-a-Service (RaaS) model and without engaging affiliates. The group distinguishes itself by using a modular ransomware payload tailored to target specific victim environments, with support for both Windows and Linux systems. It also uniquely avoids using countdown timers on its data leak site, contrasting with common ransomware group practices. While identified as a distinct entity, Frag has been linked to the tactics, techniques, and procedures of other ransomware groups like Akira and Fog, and some analysis suggests it is a variant of the HellCat/Morpheus and AidLocker ransomware families.

Aliases del actor

FELIXROOTincluyendo el desarrollodistribución de herramientas maliciosas

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownwww.breachsense.comfragerlaw.com - LockBit Data Breach
DLS / leak siteunknowngetbootstrap.comfragerlaw.com - LockBit Data Breach
Repositoriounknowngithub.comfragerlaw.com - LockBit Data Breach
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: frag
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

ArgentinaCanadaGermanySpainUnited KingdomIndiaIran, Islamic Republic ofNetherlandsSingaporeUnited States

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesCredit UnionsSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationAir Transportation

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com