Quantum is a ransomware group that emerged in August 2021 as a rebrand of the MountLocker ransomware. It is closely associated with the notorious Conti ransomware operation, with many of its members believed to be former Conti affiliates, and operates on a Ransomware-as-a-Service (RaaS) model. The group's primary motivation is financial extortion, achieved through the encryption of victim data and a 'double extortion' tactic that involves exfiltrating sensitive information and threatening its public release if a ransom is not paid. Quantum is particularly distinguished by the extreme speed of its attacks, often deploying ransomware within hours of initial network compromise, a characteristic that significantly reduces defenders' response time and sets it apart from many other ransomware operations. It cannot delete Volume Shadow Copies, a feature present in some other ransomware families.
Tecnicas MITRE
T1566.001, T1078, T1047, T1027, T1486, T1105
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
United Arab EmiratesArgentinaAustraliaBelgiumCanadaChileChinaGermanyDominican RepublicSpain
Sectores objetivo (SOCRadar)
Construction of BuildingsOther Information ServicesSoftware PublishersEnterprises & HoldingAccommodationManufacturingConstructionPublic AdministrationAdministrative &Waste Management Educational Services