Uptime Hamster: 8d 2h 36mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Coinbase Cartel

Coinbase Cartel

0 incidentes 0 paises 0 sectores apt null Ultimo: -
Ver en IntelTracker → APTTrail →
Coinbase Cartel is a cybercriminal group that emerged in September 2025, distinguishing itself from traditional ransomware actors by focusing exclusively on data exfiltration and extortion rather than employing encryption. The group operates with a business-like professionalism, utilizing staged data leaks, evidence packages for victims, and even promoting partnership programs. Assessed to be an offshoot or composed of affiliates from the Scattered LAPSUS$ Hunters ecosystem, which includes members of ShinyHunters, Scattered Spider, and Lapsus$, the group's primary motivation is financial gain through pure extortion via stolen data. It quickly rose to become one of the top ten most active extortion groups globally. The name 'Coinbase Cartel' does not indicate any affiliation with the legitimate cryptocurrency exchange Coinbase.

Actores similares

coinbasecartelransomware · 177coinbase-cartelactor · 4ransomcartelransomware · 2cartelactor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionunknownfjg4zi4opkxkvdz7mvwp7h6goe4tcby3hhkrz43pht4j3vakhy75znyd.onioncoinbasecartel
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: coinbasecartel
DLS / leak siteunknownnitter.netIdo Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.
X/Twitterunknownx.comIdo Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.
Tecnicas MITRE
T1021 - Remote Services, T1070 - Indicator Removal on Host, T1199 - Trusted Relationship, T1496 - Resource Hijacking, T1134 - Access Token Manipulation, T1567 - Exfiltration Over Web Service
Tipo
apt
Pais origen
null
Motivacion
-
Impacto
27
Actualizado
Fri, 17 Ap

Paises objetivo (SOCRadar)

United Arab EmiratesCanadaGermanyFranceIsraelJapanKorea, Republic ofUnited States

Sectores objetivo (SOCRadar)

Transportation&WarehousingInformation ServicesProfessional&Technical ServicesHealthCare & Social AssistanceOtherPublishing ServicesTelecommunicationsBanking