Skip to content
skopnix
← adversaries
Unknown · assessed origin Russia

OldGremlin

misp-galaxyrefreshed 2026-09-15

sigil

Analyst brief

OldGremlin is a Russian-speaking ransomware group that has been active for several years. They primarily target organizations in Russia, including banks, logistics, industrial, insurance, retail, and IT companies. OldGremlin is known for using phishing emails as an initial infection vector and has developed custom malware for both Windows and Linux systems. They have conducted multiple malicious email campaigns and demand large ransoms from their victims, with some reaching millions of dollars.

Take it with you
References
Early access

Track OldGremlin on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected