Adrastea is a threat actor posing as independent researchers, known for ransomware operations and sensitive data theft.
Analyst brief
Adrastea is a threat actor presenting itself as a group of independent cybersecurity researchers, yet linked to ransomware operations, data leak platforms, and network access groups. They primarily target high-profile organizations like MBDA in the defense sector, focusing on sensitive data theft and extortion. Key TTPs include exploiting critical vulnerabilities in infrastructure to gain access, exfiltrating sensitive data, and offering stolen information for sale on cybercrime forums. Defenders should prioritize vulnerability management for externally facing systems, monitor for unauthorized data exfiltration and anomalous network access, and track breach claims on underground forums.
Adrastea
unknown
Adrastea is a threat actor who has been active on cybercrime forums, claiming to have breached organizations like MBDA and offering stolen data for sale. They describe themselves as a group of independent cybersecurity experts and researchers. Adrastea has been linked to ransomware operations, data leak platforms, and network access groups. The actor has been known to exploit critical vulnerabilities in target organizations' infrastructure to gain access to sensitive data.
What sector does the Adrastea threat actor target?+
They primarily target high-profile organizations in the defense sector, citing victims like MBDA.
What are the primary TTPs used by Adrastea?+
Exploiting critical vulnerabilities to gain access to sensitive data, offering stolen information for sale on cybercrime forums, and deploying ransomware.