Ransomcortex is a ransomware-as-a-service (RaaS) group that emerged in July 2024, specializing as a crypto-ransomware operator and data broker. The group notably focused on healthcare facilities immediately upon its appearance, rapidly claiming four victims within its first month of activity before subsequently becoming inactive. Their primary motivation is financial, employing various extortion tactics including blackmail, direct extortion, double extortion, and swatting. Ransomcortex is distinguished by its brief but impactful initial campaign against the healthcare sector and its swift transition to inactivity following these early attacks.
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
BrazilCanadaFranceIrelandItalyNetherlandsUnited States
Sectores atacados
Healthcare (1)
Sectores objetivo (SOCRadar)
ManufacturingHealthCare & Social AssistanceAccommodation&Food ServicesAccommodationOffices of PhysiciansOther Amusement and Recreation IndustriesAdministration of Human Resource Programs