BrainCipher is a ransomware group active since July 2024, known for using a leaked LockBit Black build.
Analyst brief
BrainCipher is a ransomware group active since July 2024. It targets various sectors including Manufacturing, Technology, Healthcare, Energy, and Retail across the United States, Canada, United Kingdom, Belgium, Brazil, and Austria. The group utilizes a leaked LockBit Black build, likely exploits CVE-2023-28252, and demands ransom in Monero. Defenders should prioritize patching CVE-2023-28252, monitor for Monero payments, and inspect network traffic to TOR domains starting with 'brain'.
BrainCipher
activecrime
Brain Cipher emerged in July 2024. Both Windows and Linux variants are available. Brain Cipher using the leaked build of LockBit Black for their operations. The group suspected to have exploited CVE-2023-28252 (Microsoft Windows CLFS Driver Privilege Escalation Vulnerability). The Ransom demand ranges from $150,000 to $1,00,0000. Demand to be paid with Monero (XMR) cryptocurrency. In 2025, they have shifted their new Negotiation portal to new server with vanity TOR Domain starting with 'brain'.