Ransomware Group intelligence
BlueWhale
ActiveTrack BlueWhale with 4 published victims and 1 known leak locations in a single intelligence view.
Overview
BlueWhale is tracked by Breach House as a ransomware group with 4 published victims.
The group is tracked across multiple victim records in the Breach House dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 4h ago | bluewh6bk2qt6wjib7qxdtplhgbwbi3p7cgofwnshfl5xo3xgwgstrid.onion |
Top Activity Sectors (1)
- IT 2
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue BlueWhale, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: low. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: BlueWhale executes ransomware payloads through PowerShell scripts injected into legitimate processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1569.002 Service Execution Execution
What they do: BlueWhale executes malicious binaries through Windows Service installation for persistent access.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: BlueWhale adds malicious entries to Registry Run Keys to ensure recurring execution on reboot.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: BlueWhale disables antivirus tools by terminating security processes and modifying Windows Defender settings.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: BlueWhale deletes Volume Shadow Copies via vssadmin to prevent file recovery after encryption.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: BlueWhale uses file and directory discovery via PowerShell to enumerate critical system paths before encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: BlueWhale uses SMB/Windows Admin Shares to spread ransomware across networked victim machines.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: BlueWhale encrypts victim files using AES-256 encryption applied to user directories and system data.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: BlueWhale runs commands to inhibit system recovery by disabling backup services and shutdown protections.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: BlueWhale performs internal defacement by replacing victim documents with ransom notes and altered metadata.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Victims (4)
Search, filter and paginate the victim timeline for BlueWhale. Showing 1–4 of 4.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | FiferFox Minecraft Server id31711 View details | IT | |||
|
FiferFox Minecraft Server is an online gaming server that provides a platform for players to access and play Minecraft games. The server operates in the IT sector, offering various features and gameplay modes for its users. FiferFox Minecraft Server was listed as a ransomware victim associated with BlueWhale |
|||||
| Ransomware | FiferFox Minecraft Server id31711 View details | IT | |||
|
This is a basic Minecraft Server. |
|||||
| Ransomware | Satellite Developer Server id31712 View details | IT | |||
|
Satellite Developer Server is a company operating in the IT sector, likely providing services related to satellite technology and development. The company's server is a critical component of its operations, supporting the development and deployment of satellite-related projects. Satellite Developer Server was listed as a ransomware victim associated with BlueWhale. |
|||||
| Ransomware | Satellite Developer Server id31712 View details | IT | |||
|
A software developer at a company |
|||||