Projectrelic is a cybercriminal group known for Golang-based ransomware and double-extortion tactics.
Analyst brief
Projectrelic is a cybercriminal ransomware group active since mid-2022, using Golang-based ransomware. They target both Windows and Linux hosts, dwelling in networks for days or weeks to perform double-extortion tactics, exfiltrating data before encryption. The group operates a TOR-based data leak site and focuses on lateral movement and data collection prior to payload deployment. Defenders should focus on detecting anomalous internal network behavior, especially Golang-related C2 traffic, and ensure robust, regularly tested offline backups to mitigate impact.
projectrelic
crime
Project Relic emerged in mid-2022 as a Golang-based ransomware targeting Windows and Linux hosts, operating with a TOR-based data leak site and using double-extortion tactics, with operators dwelling in networks for days or weeks before encrypting.