Astro Team
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Astro Team, also known simply as Astro Team, is a threat actor group that has been observed operating from Russia according to available public reporting. The group uses the alias Astro Team in its communications and leak site postings. Public sources first associated the name with a ransomware incident affecting Eduro Healthcare in early 2021. The same alias appeared in connection with a separate ransomware attack against Hoya Vision Care later that spring.
The group’s observed targets include companies in the healthcare sector and vision care manufacturers, indicating a focus on organizations that hold sensitive personal or corporate data. Both incidents occurred in the United States, suggesting a geographic focus on North American victims. Their actions are consistent with a financially motivated strategy, as they deploy ransomware to encrypt systems and subsequently threaten to release stolen data unless a payment is made. No public reporting links the group to espionage or disruptive objectives beyond monetary extortion.
Technically, Astro Team employs ransomware that has been publicly linked to the Mount Locker family, using it to encrypt victim files and demand payment. In addition to encryption, the actors exfiltrate data prior to or during the attack, storing the stolen information on a dedicated leak site. The leak site is used to publish portions of the data as proof of the breach and to pressure victims into paying the ransom, a tactic commonly described as double extortion. Details about the initial access vectors used by Astro Team, such as phishing or vulnerability exploitation, are not disclosed in the available sources.
Attribution to a specific nation‑state sponsor has not been established; the only geographic clue is the unspecified but frequently cited Russian origin of the group. The connection to Mount Locker suggests a possible affiliation with a broader ransomware‑as‑a‑service ecosystem, though no formal criminal consortium has been named in public reports. Representative operations attributed to Astro Team include the April 2021 ransomware attack on Hoya Vision Care, which resulted in the theft of approximately 300 gigabytes of confidential corporate data, and the March 2021 intrusion into Eduro Healthcare, where about 40 gigabytes of protected health information were exfiltrated and later released after alleged ransom demands went unmet. These incidents illustrate the group’s pattern of targeting data‑rich organizations for financial gain through ransomware and data leak extortion.
Incidents
Attributed incidents are available to members.
2 incidents