OldGremlin

First seen
2020-08-01 00:00:00
Origin
RU
Primary motivation
financial-gain
Sophistication
expert
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:09:59

Targeted industries: financial-services transportation-and-logistics manufacturing retail-and-hospitality technology-and-telecommunications

Targeted regions: country_code:ru

Context

OldGremlin is a Russian-speaking ransomware group that has been active for several years. They primarily target organizations in Russia, including banks, logistics, industrial, insurance, retail, and IT companies. OldGremlin is known for using phishing emails as an initial infection vector and has developed custom malware for both Windows and Linux systems. They have conducted multiple malicious email campaigns and demand large ransoms from their victims, with some reaching millions of dollars.

Reports & references

  • rewterz.com — Rewterz Threat Alert New Ransomware Actor Oldgremlin Hits Multiple Organizations (report)
  • group-ib.com — Oldgremlin Comeback (report)
  • group-ib.com — Oldgremlin (report)

External references