Grupo de ransomware

Moondancer Ransomware

Moondancer is an emerging ransomware brand first publicly observed on 2026-08-20 through an affiliate-recruitment announcement. The program describes itself as an enterprise-grade ransomware group and solicits initial-access brokers, Windows and Active Directory penetration testers, and developers skilled in C, assembly language or Rust. The retained announcement presents affiliation as free for applicants who can provide operational value.

The program claims a Windows-only encryptor/decryptor using XChaCha20 and ECDH, variable revenue sharing and real-time support during reconnaissance, lateral movement and tool execution. It also advertises immediate neutralization of EDR/XDR products through an exploit allegedly tested against CrowdStrike, SentinelOne and Sophos. No sample, exploit, portal, victim, ransom note, wallet or independent technical analysis was identified during collection.

Moondancer is therefore best classified as an emerging, pre-operational or operationally unvalidated RaaS threat. Its risk significance derives from declared intent, recruitment breadth and interest in enterprise identity, virtualization and cloud environments—not from demonstrated attack volume or validated tooling.

INFERENCE (confidence: medium): The recruitment design signals an aspiration to build a modular ransomware labor chain spanning access acquisition, hands-on intrusion and specialist malware development. Whether a functioning core team and production-ready encryptor already exist remains unknown.

Creado por jamieres
Colaboradores 1
Última actualización 2026-08-20
Motivación principalBeneficio financiero
Primera observación2026-08-20

Aliases

Aliases

Moondancer

ATT&CK

MITRE ATT&CK

T1021Remote Services
T1078Valid Accounts
T1486Data Encrypted for Impact
T1562.001Disable or Modify Tools