Menu
Browse

Cyber Threat Actor: EpsilonRed

Aliases: 2 aliases
Actor Type Location Known Incidents
 Icon
Crime Syndicate
Russia
37 incidents
Profile

EpsilonRed, also tracked as Epsilon Red Group, is a ransomware‑operating threat actor that has been publicly linked to Russian‑speaking cybercriminal circles. The group first appeared in open‑source reporting in mid‑2021 and has been identified in multiple security advisories as a ransomware‑as‑a‑service participant that leverages double‑extortion tactics to monetize intrusions. Public attributions have consistently noted a Russian nexus, although no direct state sponsorship has been demonstrated in open sources.

The actor’s observed targeting pattern emphasizes sectors that hold sensitive personal or operational data, with healthcare providers and educational institutions appearing repeatedly in publicly reported incidents. Their strategic objective, as described in threat‑intelligence reports, is financial gain achieved through the encryption of victim networks and the threatened leakage of exfiltrated data unless a ransom is paid. No public sources have attributed espionage or purely disruptive motives to EpsilonRed’s operations.

Technical details disclosed in analyses of EpsilonRed incidents indicate that the group typically gains initial access via phishing emails containing malicious attachments or links that deliver payloads. Once inside a network, actors have been observed using legitimate administrative tools such as Cobalt Strike for lateral movement and Mimikatz for credential harvesting. The ransomware payload itself, identified as Epsilon Red, is deployed after data exfiltration to encrypt files and display a ransom note demanding payment in cryptocurrency. Post‑encryption, the group operates a leak site where they publish stolen data from victims who refuse to meet demands, reinforcing the double‑extortion model.

Publicly cited campaigns include a series of attacks on U.S. healthcare organizations in late 2021 and early 2022, where patient records and internal administrative files were allegedly exfiltrated before encryption. Educational sector incidents have also been reported, with threat actors claiming to have accessed student and staff data, including personally identifiable information and financial records. While specific victim names vary across reports, the recurring theme is the targeting of entities that manage large volumes of sensitive information, enabling the group to exert pressure through the threat of public disclosure. These observed activities constitute the currently documented operational footprint of EpsilonRed based on available open‑source material.

Incidents
Attributed incidents available to members
36 incidents
Sources
Sources available to members
33 sources