Uptime Hamster: 10d 6h 59mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21

BushidoUK ToolMatrix ThreatIntel: TheDFIRReportGroups

Fecha
18 Jun 2026
Actor
bushidouk
Tipo
Report
Pais
United States
Sector
-
Confianza
high
50
Prioridad analitica
Baja

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

0IOCs
0TTPs
bushidoukActor
United StatesPais
Executive Summary
Recurso del BushidoUK Ransomware Tool Matrix - ThreatIntel.

Key Points

  • Source: ThreatIntel/TheDFIRReportGroups.md
  • BushidoUK Tool Matrix

ThreatIntel: TheDFIRReportGroups.md

Recurso del BushidoUK Ransomware Tool Matrix - ThreatIntel.

The DFIR Report Threat Groups

> [!IMPORTANT]

> The Threat Groups mentioned in other files in this repository are highlighted in the following list from The DFIR Report. It was important to use this list of publicly available reports as the main source as it makes it so the research can be independently peer reviewed.

Most Recent PublicationRansomware/ExtortionistReport
28 April 2025Fog<a href="https://thedfirreport.com/2025/04/28/navigating-through-the-fog/" rel="noopener" target="_blank">Navigating Through The Fog</a>
31 March 2025BlackSuit<a href="https://thedfirreport.com/2025/03/31/fake-zoom-ends-in-blacksuit-ransomware/" rel="noopener" target="_blank">Fake Zoom Ends in BlackSuit Ransomware</a>
26 August 2024BlackSuit<a href="https://thedfirreport.com/2024/08/26/blacksuit-ransomware/" rel="noopener" target="_blank">BlackSuit Ransomware</a>
10 June 2024BlackCat (ALPHV)<a href="https://thedfirreport.com/2024/06/10/icedid-brings-screenconnect-and-csharp-streamer-to-alphv-ransomware-deployment/" rel="noopener" target="_blank">IcedID Brings ScreenConnect and CSharp Streamer to ALPHV Ransomware Deployment</a>
29 April 2024Dagon Locker<a href="https://thedfirreport.com/2024/04/29/from-icedid-to-dagon-locker-ransomware-in-29-days/" rel="noopener" target="_blank">From IcedID to Dagon Locker Ransomware in 29 Days</a>
1 April 2024Nokoyawa<a href="https://thedfirreport.com/2024/04/01/from-onenote-to-ransomnote-an-ice-cold-intrusion/" rel="noopener" target="_blank">From OneNote to RansomNote: An Ice Cold Intrusion</a> / <a href="https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/" rel="noopener" target="_blank">IcedID Macro Ends in Nokoyawa Ransomware</a>
29 January 2024Trigona<a href="https://thedfirreport.com/2024/01/29/buzzing-on-christmas-eve-trigona-ransomware-in-3-hours/" rel="noopener" target="_blank">Buzzing on Christmas Eve: Trigona Ransomware in 3 Hours</a>
25 September 2023Hive<a href="https://thedfirreport.com/2023/09/25/from-screenconnect-to-hive-ransomware-in-61-hours/" rel="noopener" target="_blank">From ScreenConnect to Hive Ransomware in 61 hours</a>
3 April 2023Quantum<a href="https://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/" rel="noopener" target="_blank">Malicious ISO File Leads to Domain Wide Ransomware</a> / <a href="https://thedfirreport.com/2022/04/25/quantum-ransomware/" rel="noopener" target="_blank">Quantum Ransomware</a>
4 April 2022Conti<a href="https://thedfirreport.com/2022/04/04/stolen-images-campaign-ends-in-conti-ransomware/" rel="noopener" target="_blank">Stolen Images Campaign Ends in Conti Ransomware</a> / <a href="https://thedfirreport.com/2021/09/13/bazarloader-to-conti-ransomware-in-32-hours/" rel="noopener" target="_blank">BazarLoader to Conti Ransomware in 32 Hours</a> / <a href="https://thedfirreport.com/2021/08/01/bazarcall-to-conti-ransomware-via-trickbot-and-cobalt-strike/" rel="noopener" target="_blank">BazarCall to Conti Ransomware via Trickbot and Cobalt Strike</a> / <a href="https://thedfirreport.com/2021/05/12/conti-ransomware/" rel="noopener" target="_blank">Conti Ransomware</a>
13 December 2021Diavol<a href="https://thedfirreport.com/2021/12/13/diavol-ransomware/" rel="noopener" target="_blank">Diavol Ransomware</a>
18 October 2021XingLocker<a href="https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/" rel="noopener" target="_blank">IcedID to XingLocker Ransomware in 24 hours</a>
29 March 2021REvil<a href="https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/" rel="noopener" target="_blank">Sodinokibi (aka REvil) Ransomware</a>
23 November 2020PYSA<a href="https://thedfirreport.com/2020/11/23/pysa-mespinoza-ransomware/" rel="noopener" target="_blank">PYSA/Mespinoza Ransomware</a>
5 November 2020Ryuk<a href="https://thedfirreport.com/2020/11/05/ryuk-speed-run-2-hours-to-ransom/" rel="noopener" target="_blank">Ryuk Speed Run, 2 Hours to Ransom</a> / <a href="https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/" rel="noopener" target="_blank">Ryuk in 5 Hours</a> / <a href="https://thedfirreport.com/2020/10/08/ryuks-return/" rel="noopener" target="_blank">Ryuk's Return</a>
31 August 2020NetWalker<a href="https://thedfirreport.com/2020/08/31/netwalker-ransomware-in-1-hour/" rel="noopener" target="_blank">NetWalker Ransomware in 1 Hour</a>
21 June 2020Snatch<a href="https://thedfirreport.com/2020/06/21/snatch-ransomware/" rel="noopener" target="_blank">Snatch Ransomware</a>
4 April 2020GoGoogle<a href="https://thedfirreport.com/2020/04/04/gogoogle-ransomware/" rel="noopener" target="_blank">GoGoogle Ransomware</a>

Referencias

Diamond Model

Adversary
bushidouk
Ver perfil →
Victim
BushidoUK ToolMatrix ThreatIntel: TheDFIRReportGroups
United States
Capability
Report
Infrastructure
Sin infraestructura confirmada

Referencias y enlaces

→ Perfil del actor bushidouk en el blog → Ver bushidouk en IntelTracker → Fuente OSINT: github.com→ Fuente OSINT: github.com → Buscar bushidouk en APTTrail → Repositorio APTTrail → Mas incidentes en United States → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes