brain cipher

First seen
2024-06-15 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-18 22:31:23
Profile updated
2026-07-07 13:53:20

Targeted industries: government-and-public-sector transportation-and-logistics

Targeted regions: country_code:id

Context

In mid-June 2024, a new ransomware operation named Brain Cipher emerged, notably targeting Indonesia's National Data Center. This attack disrupted immigration operations at airports and various other government services. The payload employed by this group is based on the leaked LockBit 3.0 builder. Comparative analyses have confirmed significant similarities between Brain Cipher and LockBit 3.0 samples. Notably, the attackers modified the ransomware to not only append a new extension to encrypted files but also to encrypt the filenames themselves. Additionally, it was identified that the group appears to be in its early stages, as evidenced by their use of the leaked LockBit 3.0 builder and their recent operations. After encrypting the data, the ransomware generates ransom notes named “added_extension.README.txt.” These notes contain a description of what occurred and a link to the attackers' website hosted on the Tor network.

Reports & references

  • ransomlook.io — Brain Cipher (report)
  • sentinelone.com — Brain Cipher (report)
  • watchguard.com — Brain Cipher (report)
  • vectra.ai — Brain Cipher (report)
  • group-ib.com — Brain Cipher (report)
  • wazuh.com — Detecting Brain Cipher Ransomware With Wazuh (report)
  • reuters.com — Indonesia Says It Has Begun Recovering Data After Major Ransomware Attack 2024 07 12 (report)

External references