AuditTeam is a small, financially motivated ransomware group primarily targeting the Russian technology sector.
Analyst brief
AuditTeam is a small, financially motivated ransomware group. It primarily targets organizations in the technology sector located in Russia. The threat actor employs double-extortion methodology, encrypting and exfiltrating data to publish on a dedicated data leak site. Defenders should focus on robust offline backups, network segmentation, and monitoring for unusual data exfiltration activities.
AuditTeam
activecrime
AuditTeam is a small ransomware group with approximately 5 known victims, primarily targeting organizations in East and Southeast Asia across technology and manufacturing sectors, operating a data leak site consistent with double-extortion methodology.