ALTDOS is known for ransomware, data exfiltration, and leaking customer data in Southeast Asia.
Analyst brief
ALTDOS is a threat actor group targeting entities in Southeast Asia, particularly in Singapore, Thailand, and Malaysia, impacting sectors like real estate and retail. Their primary TTPs include ransomware attacks, data exfiltration, and leaking or selling compromised sensitive customer data (names, bank account numbers, transaction details) on underground forums. The group demands ransom payments and leaks data if demands are unmet. Defenders must focus on ransomware prevention mechanisms, data loss prevention (DLP) solutions for customer and financial databases, and monitoring underground forums for exposed credentials and data dumps.
ALTDOS
unknown
ALTDOS is a threat actor group that has targeted entities in Southeast Asia, including Singapore, Thailand, and Malaysia. They have been involved in data breaches of companies in various sectors, such as real estate and retail, compromising sensitive information like customer names, bank account numbers, and transaction details. ALTDOS uses tactics like ransomware attacks, data exfiltration, and dumping data publicly or for sale on underground forums. The group has been known to demand ransom payments from victims, but also leaks data if demands are not met.