Reichsadler Cybercrime Group — Ransomware Profile

Reichsadler Cybercrime Group is the self-chosen name of a ransomware crew that Sophos X-Ops documented in October 2023 after its responders caught a failed ransomware deployment against one of its customers. The operators gained entry through CVE-2023-40044, a .NET deserialization flaw in the Ad Hoc Transfer Module of Progress Software's WS_FTP Server, and then ran the open-source GodPotato utility to escalate to NT AUTHORITY\SYSTEM. Their encryptor was not original work: it was compiled with the LockBit 3.0 builder stolen in September 2022, so the crew is a user of leaked tooling rather than part of the LockBit ransomware-as-a-service operation. The demand was unusually small for a ransomware case — 0.018 BTC, under $500, due by 15 October in Moscow Standard Time — and the encryption attempt failed because Sophos' protection blocked the payload, which was then captured for analysis. The group was unheard of before this incident, and its name borrows the German heraldic eagle that was also adopted by the Nazi regime.

Vendor research

Read the full analysis on IntelFusions