Uptime Hamster: 21d 6h 51mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza bluesky

bluesky

3 incidentes 2 paises 0 sectores threat-actor RU Ultimo: 2026-06-29
Aliases: Heyoka, Mongall, UNC94, bisonal, tonto, tontoteam, APT ICEFOG
Ver en IntelTracker → APTTrail →
BlueSky is a ransomware variant that emerged in June 2022, primarily focused on financial extortion. This ransomware family is believed with high confidence to be operated by threat actors of Russian origin. It is notable for its rapid encryption capabilities achieved through multithreading, a technique that bears code similarities to Conti v3 and Babuk ransomware. Unlike some other prominent ransomware groups, BlueSky has not been observed operating a public data leak site. The group uniquely assigns a user ID to each victim, generated based on system information, to track them and manage the decryption process.

Aliases del actor

HeyokaMongallUNC94bisonaltontotontoteamAPT ICEFOG

Actores similares

apt-icefogactor · 1apt-c-01actor · 2apt-c-27actor · 2apt-45actor · 2apt-c-37actor · 1apt-c-23actor · 1hellsing-aptactor · 1apt-c-44actor · 1apt-c-38actor · 1apt-c-12actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteupransomware.anggipradana.comRansomware Group: bluesky
Repositoriounknowngithub.comRansom Notes: bluesky (1 notes from ThreatLabz)
DLS / onionofflineccpyeuptrlatb2piua4ukhnhi7lrxgerrcrj4p2b5uhbzqm2xgdjaqid.onionCTI.FYI
Tecnicas MITRE
T1110, T1021, T1569, T1003, T1562, T1486
CVEs relacionadas
CVE-2023-27350
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

Russia (1) United States (1)

Paises objetivo (OSINT)

IndiaSaudi ArabiaUnited States

Sectores objetivo (OSINT)

Construction of BuildingsEnterprises & HoldingManufacturingConstructionPublic AdministrationEducational ServicesEnergy & Utilities Computer Systems Design and Related ServicesNational Security&International AffairsTelecommunications

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com github.com

Victimas (1)

Ransom Notes: bluesky (1 notes from ThreatLabz)18 Jun 2026
Report
bluesky - Ransom NotesEste grupo de ransomware tiene 1 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de resca…