Grupo de ransomware

ExfilSquad

ExfilSquad is an emerging financially motivated data-extortion group that surfaced publicly in July 2026 with a Tor-hosted leak site, an X account and a concentrated launch wave involving approximately fourteen to fifteen named organizations. The initial roster spans government, education, aviation, banking, insurance, technology, manufacturing, telecommunications, real estate and consumer-facing sectors across the United States, United Kingdom, Sweden and Nigeria.

The strongest publicly corroborated activity concerns the UK Department for Education and the Police National Legal Database. Victim-side reporting confirmed unauthorized access to customer-service and contact datasets affecting more than 740,000 records in aggregate. ExfilSquad posted samples and demanded payment to prevent wider publication. The Department for Education stated that it had not observed ransomware encryption and that access was limited to customer-service contact information, materially supporting a theft-first and encryption-optional assessment.

A separate Frontier Airlines claim attributed access to weakly controlled Microsoft Power Apps and Dynamics 365 Dataverse permissions. That case provides the clearest public indication of a potential access path and suggests that the group may exploit exposed or excessively permissive cloud application data rather than relying exclusively on bespoke malware. The allegation remains partly actor-sourced and should not be generalized to every ExfilSquad incident.

The group’s technical maturity remains unresolved. No confirmed ransomware payload, encrypted extension, ransom-note filename, command-and-control infrastructure, intrusion IP address, cryptocurrency wallet or malware hash has been publicly attributed with high confidence. Multiple high-impact claims, including a purported Microsoft breach, remain unverified and have attracted significant skepticism.

INFERENCE (confidence: medium-high): ExfilSquad is best modeled at present as a data-theft and extortion brand that may selectively use ransomware terminology for market positioning while prioritizing unauthorized data acquisition, sample publication and deadline-based coercion.

Creado por iQBlack CTI Team
Colaboradores 1
Última actualización 2026-08-19

ATT&CK

MITRE ATT&CK

T1190Exploit Public-Facing Application
T1530Data from Cloud Storage
T1552.001Credentials In Files

Research

OSINT seleccionado