CSIDB logo
Threat actor

Groove

Attribution profile

Type
Criminal
Location
Russia
Known incidents
2 incidents
Sources
1 source
First seen
2021-09-24
Last seen
2021-10-23
Updated
2026-08-01 00:07
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Groove is a threat actor known by that alias and is associated with a location in Russia according to available reporting. The actor has presented itself as an individual rather than an organized group, claiming to act alone to demonstrate the ease of manipulating media. Observed activity includes ransomware attacks against healthcare providers in the United States. In one incident, Groove contacted a Pennsylvania‑based medical practice with eight locations and demanded a $250,000 payment. The actor also stated that it would flood the victim’s offices and alter its website if the ransom was not paid.

The ransom demand was accompanied by messages translated from Russian that taunted the victim and urged it to return to a chat for negotiation. During the attack, the victim’s website showed intermittent outages with resource‑limit error messages, consistent with the claimed disruption. A second reported incident involved Episcopal Retirement Services, which suffered two ransomware attacks within a month and had protected health information for over four thousand individuals exposed. After the second attack, Groove listed the organization on its leak site, although the actor’s actual involvement remained unclear before the site disappeared. The intrusion method in the Episcopal Retirement Services case was not determined during the ongoing investigation.

These incidents illustrate that Groove’s observed tactics consist of deploying ransomware, threatening website modification and service disruption, and using Russian‑language communications to pressure victims. Public sources do not describe any particular exploit kits or custom tools associated with the actor. The actor’s affiliation with any state sponsor or criminal consortium has not been established, and the only geographic indicator available is the noted Russian location. Consequently, the profile of Groove remains limited to the demonstrated targeting of U.S. healthcare entities for financial extortion and the associated behaviors described above.

Incidents

Attributed incidents are available to members.

2 incidents

Sources

Sources available to members: 1 source.

CSIDB