APT73
APT73 is described in the provided content as an active ransomware group operating under a ransomware-as-a-service model. The group reportedly emerged in mid-April 2024, was first discovered on 2024-04-22, and self-proclaimed as an "APT." The content notes that much of the publicly available information about APT73 came from the LockBit ransomware group. According to the content, APT73 has targeted industrial and critical infrastructure sectors, and victim reporting in the source material spans business services, technology, financial services, public sector, and healthcare. The United States and the United Kingdom are listed as the most represented victim countries, with additional victims reported in Brazil, France, and India. The content also claims that 52.1% of victims with domains were associated with infostealer exposure. The source material lists alleged victims across government, banking, healthcare, telecom, aviation, education, utilities, and technology sectors worldwide, and references APT73-related infrastructure including multiple .onion sites and the clearnet domain eraleignews.com. A YARA rule named apt73.yar is also referenced. Known alias in the provided content: apt73.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Observables
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service group first observed in April 2024, operating leak/onion sites and publicly listing numerous victims across business services, technology, financial services, public sector, and healthcare.
Named activity cluster/group in the ransomware ecosystem targeting industrial and critical infrastructure sectors (as described in the report).
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.