HackerFeeds
All ransomware groups

coinbasecartel

177 tracked victims
·first seen 2023-05-26·last activity 2026-06-12

Group profile

CoinbaseCartel specializes in data acquisition through system access and strategic partnerships. It focus exclusively on data exfiltration—our operations never involve system encryption or operational disruption.

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078.004Valid Accounts: Cloud Accounts

    Massive focus on credential theft from SaaS platforms (Salesforce, Microsoft 365).

  • T1091Replication Through Removable Media

    Although less common, there are records of attempts via service providers (corrupted insiders/third parties).

  • T1133External Remote Services

    Abuse of VPNs and RDP using credentials harvested by infostealers or purchased from IABs (Initial Access Brokers).

  • T1566.003Phishing: Spearphishing Voice (Vishing)

    Use of voice social engineering to induce employees to authorize malicious OAuth applications.

TA0002

Execution

  • T1059.004Command and Scripting Interpreter: Unix Shell

    The shinysp1d3r loader is executed via shell scripts on ESXi systems.

  • T1059.006Command and Scripting Interpreter: Python

    Use of custom scripts that mimic legitimate tools (e.g., Salesforce Data Loader) for rapid exfiltration.

  • T1204.002User Execution: Malicious File

    Deceiving users into executing fake OAuth connectors.

TA0003

Persistence

  • T1098.003Account Manipulation: Additional Cloud Credentials

    Adding new secrets or keys to existing OAuth applications to maintain access even after password changes.

  • T1136.001Create Account: Local Account

    Creation of "ghost" administrator users on VMware hosts.

TA0005

Defense Evasion

  • T1036.005Masquerading: Match Legitimate Name or Location

    Renaming malicious binaries to names of critical VMware processes or backup tools.

  • T1070.001Indicator Removal: Clear Windows Event Logs

    Systematic cleaning of syslogs and audit logs in ESXi environments.

  • T1562.001Impair Defenses: Disable or Modify Tools

    Disabling virtual machine snapshots before encryption (when they opt for it).

TA0007

Discovery

  • T1018Remote System Discovery

    Enumeration of Active Directory objects from non-privileged user accounts.

  • T1083File and Directory Discovery

    Scanning vCenter datastores to identify critical VMs and databases.

  • T1538Cloud Service Dashboard

    Exploration of AWS/Azure consoles to identify EBS volumes and S3 instances.

TA0010

Exfiltration

  • T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage

    Use of tools like Rclone to send data to providers such as Mega or Dropbox.

TA0040

Impact

  • T1486Data Encrypted for Impact

    Secondary technique, focused on .vmdk files via shinysp1d3r loader.

  • T1657Financial Theft

    Direct extortion based on the threat of leaking data on Onion forums (DLS).

Recent victims

showing 50 of 177
DateWebsite / victimSectorCountry
2026-06-12
demand.io
Demand.ioDemand.io
TechnologyUS
2026-06-12
C
Cambridge Mobile Telematics
TechnologyUS
2026-06-05
demand.io
Demand.ioNEWDemand.io
Technology
2026-06-05
cmtelematics.com
Cambridge Mobile TelematicNEWcmtelematics.com
TechnologyUS
2026-06-02
C
Cambridge Mobile TelematicsNEW
TechnologyUS
2026-05-30
siveco.com
Siveco -siveco.com
TechnologyFR
2026-05-30
openmindnetworks.com
Openmind networksopenmindnetworks.com
TechnologyGB
2026-05-30
pragmatic.solutions
Pragmatic Solutionspragmatic.solutions
Business Services
2026-05-15Business ServicesUS
2026-05-15TechnologyUS
2026-05-13
bas.com.ar
Buenos Aires Softwarebas.com.ar
TechnologyAR
2026-05-11
ijs.si
Jozef Stefan Institute (IJS)ijs.si
EducationSI
2026-05-11HealthcareKR
2026-05-11
tabservice.com
Tab Servicetabservice.com
Business ServicesDE
2026-05-11
cassinfo.com
Cass information Systemscassinfo.com
Business ServicesUS
2023-11-20
dreyfuss.com
Dreyfuss Williams & Associates CO LPAdreyfuss.com
Business ServicesUS
2025-08-25
marlboroughpartners.com
Marlborough Partnerswww.marlboroughpartners.com
Financial ServicesGB
2026-04-23
pertanian.go.id
Kementerian Pertanianpertanian.go.id
Agriculture and Food ProductionID
2026-04-23
seatelecom.com.br
Sea Telecom Brseatelecom.com.br
TelecommunicationBR
2026-04-23
precisioncoating.com
Precision Coatingprecisioncoating.com
ManufacturingUS
2025-11-10
integer.net
Integer Holdingsinteger.net
ManufacturingUS
2026-04-23
perulng.com
Peru LNG (Hunt LNG Operating Company)perulng.com
EnergyPE
2026-04-23Business ServicesUS
2026-04-20
sig.biz
SIG.bizsig.biz
Business ServicesCH
2026-04-20TelecommunicationUS
2026-04-20
playmatestoys.com
Playmates Toysplaymatestoys.com
Consumer ServicesHK
2026-04-20EnergyFR
2026-04-18
astim.it
ASTM Groupastim.it
Business ServicesUS
2026-04-18TechnologyFR
2026-04-18Not FoundHR
2026-04-18
mccuaig.net
McCuaig and associates Engineeringmccuaig.net
Business ServicesCA
2026-04-18
evictthemforme.com
Evict them for meevictthemforme.com
Business ServicesUS
2026-04-15
theepochtimes.com
The Epoch Timestheepochtimes.com
Consumer ServicesUS
2026-04-15
uom.gr
UOM Universitywww.uom.gr
EducationMT
2026-04-15Not FoundUS
2026-04-15
epochtimes.com
Epoch Timesepochtimes.com
Consumer ServicesUS
2026-04-15
sot.gob.ec
Superintendency of territorial planningsot.gob.ec
Public SectorEC
2026-04-15
glsteel.pl
GL Steelglsteel.pl
ManufacturingPL
2026-04-15
waynebrothers.com
Wayne Brothers Constructionwaynebrothers.com
ConstructionUS
2026-04-15
questivity.com
Questivityquestivity.com
Business ServicesUS
2026-04-15
mil-pkg.com
Millenium Packagingmil-pkg.com
ManufacturingUS
2026-04-15Public SectorID
2026-04-15
rogiken.org
Rogiken / institute of Science Tokyorogiken.org
EducationJP
2026-04-15
la-maison-bleue.fr
La Maison Bleue Francela-maison-bleue.fr
Hospitality and TourismFR
2026-04-15EnergyES
2026-04-15TechnologyUS
2026-04-15Business ServicesUS
2026-04-14
idera.com
Flash Charm INC - (IDERA)idera.com
TechnologyUS
2026-04-12Consumer ServicesUS
2026-04-12Consumer ServicesUS