Uptime Hamster: 27d 15h 55mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza lv

lv

1 incidentes 0 paises 0 sectores threat-actor RU Ultimo: 2026-06-29
Aliases: Dark Halo, Nobelium, Silver Fish, la penetración de sistemas críticos, Fraternal Jackal, Ababil, ha sido identificado con la plataforma pastebin, Nigeria, Kwampirs backdoor, empresas farmacéuticas, proveedores de soluciones IT para el sector sanitario, fabricantes de equipos médicos, Powerkatz, Password Dumper, PTH, DCSync, SkeletonKey, Golden
Ver en IntelTracker → APTTrail →
LV is a ransomware group that first emerged in late 2020. It operates as a ransomware-as-a-service (RaaS) offering, primarily distinguished by its use of a modified REvil (also known as Sodinokibi) ransomware binary. The group's primary motivation is financial gain through double extortion, where they encrypt victim data and threaten to leak stolen information. While they often frame their attacks as retaliation against organizations that fail to protect data, this serves as a justification for their financially driven operations. Despite leveraging a powerful, repurposed ransomware, LV's backend infrastructure is considered less sophisticated than the original REvil operation, specifically lacking the extensive command and control network.

Aliases del actor

Dark HaloNobeliumSilver Fishla penetración de sistemas críticosFraternal JackalAbabilha sido identificado con la plataforma pastebinNigeriaKwampirs backdoorempresas farmacéuticasproveedores de soluciones IT para el sector sanitariofabricantes de equipos médicosPowerkatzPassword DumperPTHDCSyncSkeletonKeyGoldenSilver Ticketsotrosse clasifica dentro de la categoría "Malware / Tools"HellsingCycldekConimes TeamChina1937CN Teamotros mencionados en fuentes OSINT verificadasAgriculture in EUPlugXsegún informes verificadosEnergy technologyG20NGOs

Actores similares

SilverFishapt · 0DarkStorm Teamapt · 0apt-1877teamactor · 1apt-darkcaracalactor · 1apt-darkhydrusactor · 1apt-equationgroupactor · 1apt-goldenjackalactor · 1apt-greyenergyactor · 1apt-hackingteamactor · 1apt-stealthfalconactor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteupransomware.anggipradana.comRansomware Group: werewolves
DLS / leak siteunknownnitter.netDark Web Informer: ‼ New Ransomware Group: SETTRA htttp://settra5ldqwgtw5q7z5awbsvlksakyfojuc5slgrz5lvapune4fantqd[.]onion
X/Twitterunknownx.comDark Web Informer: ‼ New Ransomware Group: SETTRA htttp://settra5ldqwgtw5q7z5awbsvlksakyfojuc5slgrz5lvapune4fantqd[.]onion
Forounknownnitter.netDaily Dark Web: Pinned: New Linux "pedit COW" Privilege Escalation Exploit Published Security researcher Massimiliano Oldani has released a public proof-of-concept (PoC) exploit, **packet_edit_meme**, for the Linux kernel vulnerability **CVE-2026-46331**, nicknamed **pedit COW**. * The flaw resides in Linux's **net/sched act_pedit** traffic control subsystem and allows an unprivileged local user to escalate privileges to **root** by corrupting shared page-cache memory.
Forounknownx.comDaily Dark Web: Call of Duty: Mobile Internal Offsets Allegedly Released A forum user has shared what they claim is an internal `offsets dump.cs` file for the global version of Call of Duty: Mobile (package: `com.activision.callofduty.shooter`). The post includes a public download link and states the file will be reposted if the original link becomes unavailable.
Forounknownnitter.netDaily Dark Web: Call of Duty: Mobile Internal Offsets Allegedly Released A forum user has shared what they claim is an internal `offsets dump.cs` file for the global version of Call of Duty: Mobile (package: `com.activision.callofduty.shooter`). The post includes a public download link and states the file will be reposted if the original link becomes unavailable.
DLS / leak siteunknownnra.lvRansomware News: Noticis kiberuzbrukums Latvijas Valsts mežiem; drošības apsvērumu dēļ slēgts LVM GEO, karšu sistēma un "Mednis" [papildināts]
DLS / leak siteunknownnitter.netIdo Cohen: The Icarus supply chain extortion campaign continues to unfold. The group has now added 5 additional victims, all with their identities partially concealed. The guessing game has officially begun. How many organizations were impacted through this supply chain incident? And are we witnessing the emergence of a serious competitor to CLOP in the supply chain extortion arena? We'll know more soon.
X/Twitterunknownx.comIdo Cohen: The Icarus supply chain extortion campaign continues to unfold. The group has now added 5 additional victims, all with their identities partially concealed. The guessing game has officially begun. How many organizations were impacted through this supply chain incident? And are we witnessing the emergence of a serious competitor to CLOP in the supply chain extortion arena? We'll know more soon.
DLS / leak siteunknownnitter.netIdo Cohen: The Icarus supply chain extortion campaign continues to unfold. The group has now added 5 additional victims, all with their identities partially concealed. The guessing game has officially begun. How many organizations were impacted through this supply chain incident? And are we witnessing the emergence of a serious competitor to CLOP in the supply chain extortion arena? We'll know more soon.
Repositoriounknowngithub.comvampirebot indicators and references
Webunknownwww.virustotal.comvampirebot indicators and references
Webunknownwww.virustotal.comvampirebot indicators and references
Webunknownwww.virustotal.comvampirebot indicators and references
Webunknownwww.virustotal.comvampirebot indicators and references
X/Twitterunknownx.comvampirebot indicators and references
X/Twitterunknownx.comvampirebot indicators and references
X/Twitterunknownx.comvampirebot indicators and references
Repositoriounknowngithub.comvampirebot indicators and references
Webunknownraw.githubusercontent.comvampirebot indicators and references
X/Twitterunknowngithub.comvampirebot indicators and references
DLS / leak siteunknownnitter.netGroup-IB Threat Intelligence: As browser security evolves, attackers are moving beyond traditional cookie theft. #SilabRAT advertises browser profile cloning, allowing operators to replicate a victim's browser environment, including extensions, storage, and fingerprinting artifacts. This enables access to authenticated sessions that may otherwise resist conventional session hijacking techniques. #CyberThreats #ThreatIntelligence
X/Twitterunknownx.comGroup-IB Threat Intelligence: As browser security evolves, attackers are moving beyond traditional cookie theft. #SilabRAT advertises browser profile cloning, allowing operators to replicate a victim's browser environment, including extensions, storage, and fingerprinting artifacts. This enables access to authenticated sessions that may otherwise resist conventional session hijacking techniques. #CyberThreats #ThreatIntelligence
DLS / leak siteunknownwww.vozdaplanicie.ptRansomware News: Autarquia de Serpa alvo de ataque informático | Rádio Voz da Planície - 104.5FM - Beja
DLS / onionofflinerbvuetuneohce3ouxjlbxtimyyxokb4btncxjbo44fbgxqy7tskinwad.onionCTI.FYI
DLS / onionoffline4qbxi3i2oqmyzxsjg4fwe4aly3xkped52gq5orp6efpkeskvchqe27id.onionCTI.FYI
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (OSINT)

ArmeniaArgentinaAustraliaBosnia and HerzegovinaBrunei DarussalamBolivia, Plurinational State ofBrazilCanadaSwitzerlandChina

Sectores objetivo (OSINT)

Construction of BuildingsFood ManufacturingOther Information ServicesMonetary Authorities-Central BankSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationManufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com