Quantum
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Quantum is a ransomware‑operating threat actor that uses the alias Quantum and has been identified as an offshoot of the Conti ransomware operation with ties to earlier MountLocker variants. The group’s location is noted as Russia in the provided context, indicating a possible Russian nexus for the operation.
Quantum’s targeting pattern, as reflected in the publicly reported incidents, includes government agencies, healthcare providers, and social‑services organizations across multiple regions. The group attacked a Dominican Republic government agricultural agency, a county social services department in California, and an Australian medical laboratory that serves patients in New South Wales and Queensland. In each case the actors demanded a ransom payment or threatened to release stolen data, indicating a financially motivated extortion strategy that leverages data leakage as coercion.
The group’s tactics, techniques and procedures are consistently linked to the Quantum ransomware family, which is described as an offshoot of Conti with connections to earlier MountLocker variants. Their operations have relied on compromised infrastructure that was traced to IP addresses in the United States and Russia, suggesting the use of hijacked servers or networks as an initial access vector. Quantum also operates under a ransomware‑as‑a‑service model, claiming responsibility on leak sites and publishing large data dumps—such as an 86‑gigabyte file in the Medlab Pathology case and a 32‑gigabyte claim in the Tehama County incident—to pressure victims into paying.
Representative operations attributed to Quantum include the August 2022 ransomware attack on the Dominican Republic’s Instituto Agrario Dominicano, which encrypted physical and virtual servers and prompted a $650,000 ransom demand with a threat to release over one terabyte of data; the April 2022 incident against Tehama County Social Services in California, where the group claimed to have exfiltrated 32 GB of personally identifiable information and protected health information; and the February 2022 breach of Australian Clinical Labs’ Medlab Pathology systems, in which Quantum asserted responsibility, posted a large data file on a leak site, and exposed personal and medical details of hundreds of thousands of individuals. These incidents illustrate the group’s recurrent focus on high‑value data held by public‑sector and health‑related entities, using ransomware and data‑leak threats to achieve financial gain.
Incidents
Attributed incidents are available to members.
3 incidents