Groove
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On Aug. 22, Orange announced a new ransomware affiliate program called “ Groove ,” which claimed to be an aggressive, financially motivated criminal organization dealing in industrial espionage for the previous two years.
On Aug. 22, Orange announced a new ransomware affiliate program called “ Groove ,” which claimed to be an aggressive, financially motivated criminal organization dealing in industrial espionage for the previous two years.
Techniques & procedures
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Stealth
1 techniquePolymorphism involves encrypted viruses where the decryption routine code is variable.
Impact
2 techniquesOn January 1, 2021, a new user “Babuk” registered on the crime forum Verified... “We run an affiliate program,” Babuk explained in their introductory post on Verified.
Babuk continued to post databases stolen from companies that refused to pay a ransom, but they posted the leaks to both their victim shaming blog and to multiple cybercrime forums... Babuk announced they were shuttering the affiliate program and its encryption services, and that they would now focus on data theft and extortion instead.
Other
1 techniqueRecent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Groove is described as a ransomware affiliate program announced on RAMP, though later characterized by Boriselcin as largely a pet project intended to provoke media and the security industry.
First .EXE-infecting virus using MtE; also targeted many anti-virus products.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.