Coinbasecartel Ransomware

Description Summary

CoinbaseCartel specializes in data acquisition through system access and strategic partnerships. It focus exclusively on data exfiltration—our operations never involve system encryption or operational disruption.

Threat Actor

Infostealer-driven access; part of Scattered Lapsus$ Hunters (ShinyHunters/Scattered Spider/Lapsus$); 48h contact + 10-day BTC window. No link to the real Coinbase.

Technical Indicators

Encryption Extension
N/A — no encryption (data extortion)
Encryption Algorithm
N/A
Ransom Note Name
N/A
Targeted Industries
Healthcare, Technology, Transportation/Logistics
First Seen
15 September 2025
Last Seen
Active (160+ victims)
Geographical Location
Global

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
Exfiltration x 1 T1567 Exfiltration Over Web Service (leak site)
Initial Access x 2 T1190 Exploit Public-Facing Application
T1078 Valid Accounts