0mega
Group profile
0mega is a double-extortion ransomware group that emerged in May 2022, targeting businesses across multiple sectors worldwide by encrypting files and threatening to leak stolen data; it also pivoted to cloud-based extortion by compromising Microsoft 365 admin accounts.
MITRE ATT&CK TTPs
Initial Access
T1078Valid Accounts
Access was obtained through the compromise of global Microsoft SaaS administrator accounts that were weakly protected.
Privilege Escalation
T1136Create Account: Cloud Account
After gaining initial access, the group created a new user in Active Directory (AD) named "0mega" with multiple administrator roles (e.g., Global Administrator, SharePoint Administrator) to maintain maximum control.
Defense Evasion
T1531Account Access Removal
The group systematically deleted over 220 corporate administrator accounts within a two-hour period, impairing the victim's ability to respond and recover.
Collection
T1119Automated Collection
The group collected sensitive data using the obtained permissions.
Exfiltration
T1041Exfiltration Over C2 Channel
Data was exfiltrated from environments such as the victim's SharePoint, consistent with a double extortion tactic.
Impact
T1486Data Encrypted for Impact
The attack used AES-256 or RSA encryption on critical files after network mapping, blocking legitimate access. In some cases, the focus was solely on exfiltration and extortion without encryption.
T1490Inhibit System Recovery
The ransomware searched for and disabled connected or online backups to prevent quick data recovery without paying the ransom.
Recent victims
| Date | Website / victim | Sector | Country |
|---|---|---|---|
| 2024-01-25 | Four Hands LLCfourhands.com | Business Services | US |
| 2023-10-17 | R Rotorcraft Leasing Company | Transportation/Logistics | |
| 2023-10-04 | U US Liner Company & American Made LLC | Manufacturing | |
| 2023-02-12 | Aviacode (GeBBS)gebbs.com | Healthcare | |
| 2023-01-09 | Aviacodeaviacode.com | Healthcare | |
| 2022-09-15 | Nextlabsnextlabs.com | Business Services | US |
| 2022-07-14 | M Maxey Moverley | Business Services |

