Threat Actor Characterization
You’re viewing the read-only version.
Sign in for analyst tools (editors, promote draft, file/relations management, etc.)
FSOCIETY
ID: 6937f54c4a17dbbd566c01941af2b20f
Cybercrime
Cybercriminal
Threat types: —
Progress: 81%
Completeness: 77%
Freshness: 90%
Operation zone: —
Aliases
Limited alias preview
| fsociety 1337 | fsociety1337 | — | — |
Actor Network Graph
Open Network GraphMITRE ATT&CK®
confidence: medium
FSOCIETY (aka Flocker) is an OSINT-reported ransomware-as-a-service (RaaS) cluster associated with double-extortion operations and public leak-site signaling, with reported ecosystem linkage to FunkSec.
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1486 | Data Encrypted for Impact | TA0040 | |
| T1565.001 | Stored Data Manipulation | TA0040 |
|
| T1657 | Financial Theft | TA0040 | |
| T1567 | Exfiltration Over Web Service | TA0010 |
|
| T1560 | Archive Collected Data | TA0009 |
|
| T1078 | Valid Accounts | TA0001 TA0003 TA0004 TA0005 |
|
| T1190 | Exploit Public-Facing Application | TA0001 |
|
| T1059 | Command and Scripting Interpreter | TA0002 |
|
| T1021.001 | Remote Desktop Protocol | TA0008 |
|
| T1490 | Inhibit System Recovery | TA0040 |
|
Executive brief
now
Saved successfully.
Hunting Playbook
now
Saved successfully.
IOC Appendix
now
Saved successfully.
OSINT Library
now
Saved successfully.