Rorschach
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known as the Rorschach ransomware gang, also tracked under the aliases BabLock and Rorschach, operates from the United States of America. Public reporting links the group to ransomware operations that have impacted organizations in the telecommunications and education sectors. In the telecom case, the gang encrypted files on an Infrastructure‑as‑a‑Service platform, disrupting VoIP, VPN and television services, which indicates a focus on critical communication infrastructure. The education sector incident involved a third‑party file‑transfer compromise that exposed student and employee data, showing the group’s willingness to exploit supply‑chain relationships to reach victims. Incident responders noted that the gang left behind specific malicious executables that were shared as indicators of compromise to aid detection. These observed victims suggest that the actor’s primary objective is financial gain through ransomware extortion rather than espionage or pure disruption.
Technical details from the attacks reveal a consistent reliance on DLL sideloading techniques to execute malicious code. The gang abused legitimate security products such as Trend Micro and BitDefender, loading harmful DLLs through trusted processes like Notepad to evade detection. In addition, the actor exploited a known vulnerability in the MOVEit Transfer application to gain indirect access to victim networks via a compromised vendor. This combination of living‑off‑the‑land binaries and third‑party software flaws illustrates a tooling style that blends stealthy payload delivery with opportunistic vulnerability exploitation. The ransomware deployed in the telecom attack was noted for its rapid encryption speed, which contributed to widespread service disruption. The ultimate payload in both cases was ransomware designed to encrypt files and demand payment for decryption keys.
Public attribution beyond the actor’s geographic base in the United States has not been established, and no clear links to state sponsors or larger criminal consortia have been disclosed in open sources. The Chilean telecommunications incident and the MOVEit‑related university breach are frequently cited as representative operations that showcase the group’s reach and methodology. The MOVEit exploitation linked the actor to a broad campaign that affected numerous organizations worldwide. While the actor continues to be monitored by security researchers and national CSIRTs, further details about its internal structure, affiliate network or revenue remain unavailable in the public domain. Consequently, any profile of the Rorschach/BabLock gang must remain confined to the observed tactics, targets and outcomes documented in the reported incidents.
Incidents
Attributed incidents are available to members.
3 incidents