Ransomware Intelligence

brain cipher

Ransomware group profile

24Victims
70Impact score

Description

Brain Cipher Ransomware is a financially motivated cybercriminal group known for deploying sophisticated ransomware attacks on large organizations since the early 2020s. The group employs advanced tactics such as double extortion, complete network infiltration, and data exfiltration to maximize ransom payouts. Their operations have targeted sectors including healthcare and finance, demonstrating a willingness to disrupt critical services for financial gain.

Key insights

  • Targets large organizations to maximize ransom payouts.
  • Utilizes double extortion tactics, threatening data release if ransoms are not paid.
  • Employs a modified variant of the LockBit 3.0 ransomware.
  • Engages in extensive network infiltration and data exfiltration before deployment.
  • Incorporates zero-day vulnerabilities and social engineering in their attacks.
  • Ransom demands typically range from $150,000 to $8 million, primarily paid in Monero.

Threat Level & Status Breakdown

For brain cipher · Based on incidents in selected period

4.8threat level
Aggressiveness7/ 10
Lethality2.3/ 10
Criticality5.1/ 10

Status Breakdown

Data Leaked45.8%11
Claimed41.7%10
First seenJul 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 18, 2026

Recent activity

Monthly attack count for brain cipher in the selected period

24Total attacks
5peak in Oct
2.4avg / month
↑ 1 vs first month
JulAugSepOctJanFebMarAprMayJun02468

Intelligence

IOCs, YARA/Sigma rules, and related families for brain cipher

  1. 71c109f3bf4da2fc0173b9bcff07e979
  2. 9c5698924d4d1881efaf88651a304cb3
  3. 0da1f4ede654e83241eaad7719a708a0
  4. 41050b2b9f619cdd9916e3bdd5b9f2f9
  5. 8b3a45ebb7f2331e90ac57a2a20536fd
  6. 714b31629c37dee57038ca4e52ef65ac
  7. 448f1796fe8de02194b21c0715e0a5f6
  8. a0efa7fb6dff1e035510ec1f42e083e4
  9. 8dbd57b042bc63b9ecdc9e3e5506ce85
  10. 523c501118ef5d7957ce54aee86d9b1d
  11. b32a8951fc4c2e4c2d63d17200ca0032
  12. f94d17b5f232e9cfd2255ca9823cb18a
View full IOC feed20 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for brain cipher

Other

T1486

T1486

T1490

T1490

T1041

T1041

T1070

T1070

T1059

T1059

T1562

T1562

T1021

T1021

T1134

T1134

T1548.002

T1548.002

T1021.001

T1021.001

T1210

T1210

T1080

T1080

Victims(24)

CompanyDomainCountryIndustryStatusDiscovered
anglomoil.comEnergy & Utilities
Claimed
4 days ago
alu-rex.comManufacturing
Data Leaked
4 days ago
squamish.netTechnology
Data Leaked
18 days ago
sheppadviser.com.auAU AustraliaProfessional Services
Data Leaked
29 days ago
ice.org.ukGB United KingdomEducation
Data Leaked
about 1 month ago
bridgeway-consulting.co.ukGB United KingdomProfessional Services
Data Leaked
about 2 months ago
soundinsurance.caCA CanadaFinancial Services
Data Leaked
2 months ago
endeavourautomotive.co.ukGB United KingdomManufacturing
Data Leaked
2 months ago
Eworldmeeworldme.comAE United Arab EmiratesTechnology
Data Leaked
2 months ago
liteline.comUS United StatesTechnology
Data Leaked
4 months ago
westonconsulting.comUS United StatesProfessional Services
Data Leaked
4 months ago
exceldor.caCA CanadaOther
Data Leaked
4 months ago
flbgroup.comGB United KingdomProfessional Services
Unknown
5 months ago
kisnet.co.jpJP JapanTechnology
Unknown
5 months ago
nwlr.caCA CanadaTechnology
Unknown
5 months ago
fsbgroup.caCA CanadaFinancial Services
Claimed
8 months ago
semag.frFR FranceEnergy & Utilities
Claimed
8 months ago
axxia.frFR FranceManufacturing
Claimed
8 months ago
oxfordcounty.caCA CanadaGovernment & Defense
Claimed
8 months ago
cdom.orgUS United StatesEducation
Claimed
8 months ago

Page 1 of 2