SYMBOLCOMMON_NAMEaka. SYNONYMS

Storm-0829  (Back to overview)

aka: DEV-0829, Nwgen Team

Nwgen is a group that focuses on data exfiltration and ransomware activities. They have been found to share techniques with other threat groups such as Karakurt, Lapsus$, and Yanluowang. Nwgen has been observed carrying out attacks and deploying ransomware, encrypting files and demanding a ransom of $150,000 in Monero cryptocurrency for the decryption software.


Associated Families

There are currently no families associated with this actor.


References
2022-11-15README_SYNACKCynthia Brumfield
Cybercrime is more of a threat than nation-state hackers
Storm-0829
2022-07-11Twitter (@cglyer)Christopher Glyer
Tweet on LAPSUS$/DEV-0537
Storm-0829
2022-04-08DataBreaches.netDissent
East Tennessee Children’s Hospital updates information on ransomware incident
Storm-0829
2022-02-17enigmasoftCagedTech
Nwgen Ransomware
Storm-0829

Credits: MISP Project