HackerFeeds
All ransomware groups

0mega

7 tracked victims
·first seen 2022-07-14·last activity 2024-01-25

Group profile

0mega is a double-extortion ransomware group that emerged in May 2022, targeting businesses across multiple sectors worldwide by encrypting files and threatening to leak stolen data; it also pivoted to cloud-based extortion by compromising Microsoft 365 admin accounts.

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078Valid Accounts

    Access was obtained through the compromise of global Microsoft SaaS administrator accounts that were weakly protected.

TA0004

Privilege Escalation

  • T1136Create Account: Cloud Account

    After gaining initial access, the group created a new user in Active Directory (AD) named "0mega" with multiple administrator roles (e.g., Global Administrator, SharePoint Administrator) to maintain maximum control.

TA0005

Defense Evasion

  • T1531Account Access Removal

    The group systematically deleted over 220 corporate administrator accounts within a two-hour period, impairing the victim's ability to respond and recover.

TA0009

Collection

  • T1119Automated Collection

    The group collected sensitive data using the obtained permissions.

TA0010

Exfiltration

  • T1041Exfiltration Over C2 Channel

    Data was exfiltrated from environments such as the victim's SharePoint, consistent with a double extortion tactic.

TA0040

Impact

  • T1486Data Encrypted for Impact

    The attack used AES-256 or RSA encryption on critical files after network mapping, blocking legitimate access. In some cases, the focus was solely on exfiltration and extortion without encryption.

  • T1490Inhibit System Recovery

    The ransomware searched for and disabled connected or online backups to prevent quick data recovery without paying the ransom.

Recent victims

DateWebsite / victimSectorCountry
2024-01-25
fourhands.com
Four Hands LLCfourhands.com
Business ServicesUS
2023-10-17
R
Rotorcraft Leasing Company
Transportation/Logistics
2023-10-04
U
US Liner Company & American Made LLC
Manufacturing
2023-02-12
gebbs.com
Aviacode (GeBBS)gebbs.com
Healthcare
2023-01-09Healthcare
2022-09-15Business ServicesUS
2022-07-14
M
Maxey Moverley
Business Services