CSIDB logo
Threat actor

NoEscape

Attribution profile

Type
Crime Syndicate
Location
Russia
Known incidents
18 incidents
First seen
2022-02-12
Last seen
2023-10-01
Updated
2026-08-28 16:42
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

NoEscape is a ransomware group that operates under the alias NoEscape and has been identified as likely based in Russia. The group first appeared in May 2023 and was observed advertising its services on the cybercriminal forum RAMP. Its ransomware is written in C++ and is not derived from previously leaked or stolen source code, indicating a custom-built toolset.

The actors have demonstrated a pattern of targeting organizations across multiple sectors, including sports clubs, international bodies, educational foundations, financial services firms, and manufacturing companies. Victims have been located in Europe and North America, reflecting a transnational scope. Their primary objective appears to be financial gain, achieved through the deployment of ransomware coupled with a double‑extortion model that threatens to publish stolen data unless a payment is made.

Typical tactics involve gaining unauthorized access to a network, exfiltrating volumes of data ranging from tens to over one hundred gigabytes, and then encrypting systems to disrupt operations. The group maintains a leak site where it posts countdown timers and releases portions of the stolen information to increase pressure on victims. Ransom demands have varied from hundreds of thousands to several million dollars, and the group has followed through on publishing data when payments were not received, as seen in the case of the Fondation de Verdeil.

Representative incidents illustrate the group’s activity: a French basketball club was compromised alongside dozens of other entities, with approximately 32 GB of personal and financial data taken; the International Joint Commission reported the theft of 80 GB of contractual and geological files; and an Italian financial services firm, CreditTeam, saw roughly 121 GB of client passports, credit‑card details and internal documents exfiltrated. Additional attacks on Hawaii Community College and on manufacturing firms in the United States and the Netherlands further demonstrate the group’s reach and its reliance on data theft and ransom demands as a core operational method.

Incidents

Attributed incidents are available to members.

18 incidents
CSIDB