Brain Cipher ransomware surfaced in mid-2024, rapidly gaining notoriety after a high-impact attack on Indonesia’s National Data Center, which disrupted over 160 government services including immigration systems. The group operates with a double-extortion model, encrypting data using a LockBit 3.0-based payload (Salsa20/RSA hybrid) and threatening leaks via a Tor-hosted portal. Distinct behaviors include encrypting both file contents and filenames, and customizing encrypted file names with appended random extensions. Initial access methods include phishing and purchases from initial-access brokers. Ransom demands have ranged from tens of thousands up to $8 million USD, though victims have sometimes been offered decryption keys without payment. Victims span sectors such as government, healthcare, education, media, and manufacturing across Southeast Asia, Europe, and the Americas.
We have a lot of confidential documents. If you think you are here by mistake, please contact us at brain.dataleak@cyberfear.com
sheppadviser.com.au
We have more 350GB of data. If you think you are here by mistake, please contact us at brain.dataleak@cyberfear.com
ice.org.uk
We have more 1TB of data. If you think you are here by mistake, please contact us at brain.dataleak@cyberfear.com
bridgeway-consulting.co.uk
We have 500GB of data. If you think you are here by mistake, please contact us at brain.dataleak@cyberfear.com
soundinsurance.ca
We have 500GB of data. If you think you are here by mistake, please contact us at brain.dataleak@cyberfear.com
endeavourautomotive.co.uk
We have 150GB of data. If you think you are here by mistake, please contact us at brain.dataleak@cyberfear.com
eworldme.com
We have 300GB of data. If you think you are here by mistake, please contact us at brain.dataleak@cyberfear.com
liteline.com
We have 350GB of data. If you think you are here by mistake, please contact us at brain.dataleak@cyberfear.com
westonconsulting.com
We have 800GB of data. If you think you are here by mistake, please contact us at brain.dataleak@cyberfear.com
exceldor.ca
We have about 1.5 TB of data from the company's servers. We will publish some of it in the near future. If you think you are here by mistake, please contact us at brain.dataleak@cy...
flbgroup.com
kisnet.co.jp
nwlr.ca
fsbgroup.ca
semag.fr
axxia.fr
oxfordcounty.ca
cdom.org
bmsi.org
bw-lv.de
VIRTUALWEB.US
jorgefernandez.es
ddecor.com
ruizre.es
soundtransit.org
valedolobo.com
edisoft.es
iycsa.com.co
mbmdubai.com
neatem.fr | Update!
Pulmonary Physicians of South Florida Clinics | Data security breach!
neatem.fr
Cirion Technologies
It seems that it was easier to pay and calmly fix everything.