MadCat is a short-lived fraudulent ransomware operation from 2023 targeting criminals on the dark web with fake scams.
Analyst brief
MadCat is a reportedly fraudulent ransomware operation that briefly emerged in late 2023, likely linked to scammers targeting other criminals on the dark web with fake stolen passport offers. The group primarily targets other criminal actors, particularly those seeking illicit documents on underground forums. Its primary TTPs and tools involve fake ransomware announcements, dark web forum usage, and social engineering for fraud; however, its leak site went inactive shortly after appearing, casting doubt on any actual ransomware capabilities. Defenders should remain vigilant against such fake ransomware claims on the dark web, avoid overreacting to unverified ransomware reports targeting the organization, and monitor threat intelligence sources for these deceptive tactics employed among cybercriminals.
madcat
crime
MadCat is a suspected fraudulent ransomware operation that surfaced briefly in late 2023, apparently linked to scammers targeting other criminals on the dark web with fake stolen passport offers; its leak site appeared dead shortly after announcement, casting doubt on whether it ever operated as a genuine ransomware group.
No, MadCat is suspected to be a fraudulent ransomware operation. Its leak site became inactive shortly after being announced, casting doubt on any actual ransomware capabilities.
Who did the MadCat group primarily target?+
MadCat primarily targeted other criminal actors, particularly those seeking illicit documents on the dark web.