OldGremlin — Ransomware Profile

OldGremlin is a financially motivated ransomware crew first documented by Singapore-based vendor Group-IB, which traced its earliest observed intrusion to the turn of March and April 2020. It is a rarity among big-game ransomware operations because its victim set is overwhelmingly Russian, spanning banking, logistics, industry, insurance, retail, real estate and software development. Access is won through phishing email and followed by a home-built toolkit whose components share a "Tiny" naming convention — TinyPosh, TinyNode, TinyFluff, TinyShell and the TinyCrypt encryptor, which by 2022 also existed as a Go-written build aimed at Linux hosts. The operators are patient rather than opportunistic: Group-IB measured an average of 49 days of dwell time before encryption, counted 16 attributed campaigns by late 2022, and recorded a largest-ever ransom demand of $16.9 million. Reported post-compromise tradecraft includes scheduled-task persistence, Cobalt Strike, and privilege escalation via Cisco AnyConnect flaws CVE-2020-3153 and CVE-2020-3433. After a lull, Kaspersky reported fresh OldGremlin intrusions in early 2025 against manufacturing, healthcare, retail and technology firms, tying them to the group through consistent tradecraft and a re-used cryptographic public key from earlier campaigns.

Also tracked as

TinyScouts

Vendor research

Read the full analysis on IntelFusions