Coinbase Cartel — Data Exfiltration-Only Ransomware Group Targeting Healthcare, Tech & Transportation
Coinbase Cartel (TL-2026-0319), also tracked as Coinbase Cartel, is a high-severity ransomware operation, first published 2026-04-06. It is attributed to Coinbase Cartel (Russia) with medium confidence, affects VMware ESXi, maps to 21 MITRE ATT&CK techniques (T1018, T1021, T1041), and is covered by 9 detection rules and 15 indicators of compromise.
Key facts for TL-2026-0319
- Threat ID
- TL-2026-0319
- Also known as
- Coinbase Cartel, shinysp1d3r Group
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-04-06
- Last reviewed
- 2026-04-06
- Attribution
- Coinbase Cartel
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- healthcare, technology, transportation, financial-services, manufacturing, consumer-services, telecommunications, legal, energy, government, education, media
- Target regions
- North America, Europe, Middle East, Asia
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Coinbase Cartel
Malware and tooling: shinysp1d3r, Custom Python Salesforce Data Loader mimic, shinysp1d3r
Coinbase Cartel is a financially motivated cyber-extortion collective that emerged in September 2025, rapidly accumulating 118+ victims across 17 industries by April 2026. Formed from affiliates of ShinyHunters, Scattered Spider, and Lapsus$, the group exclusively exfiltrates data without deploying encryption, operates a dark web leak site with auction capabilities, maintains a $2M+ zero-day acquisition budget, and is actively developing the shinysp1d3r ESXi-targeted ransomware for future double-extortion operations.
How Coinbase Cartel works
Coinbase Cartel is a financially motivated extortion collective that first appeared on the dark web in September 2025, claiming 14 victims in its inaugural month. The group is composed of affiliates from well-known threat actor ecosystems including ShinyHunters, Scattered Spider, and Lapsus$, combining their expertise in credential abuse, social engineering, and large-scale data theft.
Unlike traditional ransomware operators, Coinbase Cartel employs a data-theft-first extortion strategy — systematically exfiltrating sensitive data without deploying encryption payloads. This approach makes their intrusions quieter, faster to execute, and significantly harder to detect through conventional ransomware monitoring. Victims are listed on a Tor-hosted data leak site organized into HOME, AUCTIONS, PARTNERSHIPS, and CONTACTS sections, with victim statuses tracked as active, leaking, or leaked.
The group's initial access strategy combines multiple vectors: social engineering campaigns, insider bribery schemes, vishing attacks that trick employees into authorizing malicious OAuth applications, and procurement of access through Initial Access Brokers (IABs). They also acquire exposed credentials and compromise administrative accounts through credential stuffing and reuse attacks.
In cloud environments, Coinbase Cartel leverages custom Python scripts designed to mimic legitimate tools such as the Salesforce Data Loader, enabling mass data exfiltration from CRM systems and cloud APIs without triggering security alerts. For on-premise targets, particularly VMware ESXi infrastructure, the group deploys an in-memory loader called shinysp1d3r that executes via shell scripts on ESXi hosts, retrieving encryptors and launching parallel VMDK encryption while disabling snapshots to hamper recovery efforts. While shinysp1d3r is still under active development as a RaaS offering, its deployment signals an imminent transition to double-extortion capabilities.
Persistence is maintained through long-lived OAuth tokens, creation of hidden accounts, and injection of SSH keys on compromised servers. Defense evasion tactics include disabling syslog forwarding, mass log truncation, and system-wide settings manipulation. The group communicates with victims through a chat interface, providing 48 hours for initial contact and a 10-day deadline for payment negotiation. Payment is accepted exclusively in Bitcoin.
Coinbase Cartel operates a non-RaaS business model but actively recruits partners who can demonstrate evidence of successful compromises, offering flexible compensation through fixed-rate agreements or revenue-sharing models. In October 2025, the group announced a zero-day acquisition budget exceeding $2 million, signaling advanced operational capability and sustained investment in offensive tooling.
By December 2025, Coinbase Cartel ranked among Bitdefender's Top 10 Ransomware Groups. As of April 2026, the group has claimed 118+ victims spanning 17 industries, with Technology (39 victims), Transportation/Logistics (8), Financial Services (8), Manufacturing (8), and Consumer Services (8) representing the most impacted sectors. Geographically, the United States leads with 34 victims, followed by the UAE (12), Germany (9), Canada (6), and France (6). Notably, the group breached 10 UAE healthcare organizations in a single month, demonstrating both the scale and sector-specific focus of their operations. High-profile victims include Illumina, SK Telecom, Staples, JBS Brazil, CEVA Logistics, Kuehne + Nagel, and Dolby Laboratories.
The 39.2% infostealer correlation rate among victims suggests Coinbase Cartel may leverage infostealer-harvested credentials as an initial access vector, further complicating attribution and detection efforts.
MITRE ATT&CK techniques used in TL-2026-0319
discovery
T1018 Remote System Discovery; T1580 Cloud Infrastructure Discovery
lateral-movement
exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
execution
T1059 Command and Scripting Interpreter
privilege-escalation
T1068 Exploitation for Privilege Escalation
defense-evasion
T1070 Indicator Removal; T1078 Valid Accounts
command-and-control
persistence
T1098 Account Manipulation; T1136 Create Account
collection
T1119 Automated Collection; T1213 Data from Information Repositories
initial-access
T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566 Phishing
impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery
credential-access
T1528 Steal Application Access Token
defense-impairment
Affected products and versions in Coinbase Cartel
- VMware — ESXi
Vulnerable versions: 6.x; 7.x; 8.x - Salesforce — CRM Platform
Vulnerable versions: All versions (API abuse) - Microsoft — Windows Server
Vulnerable versions: 2016; 2019; 2022 - Linux — Enterprise Linux
Vulnerable versions: All distributions
Remediation for Coinbase Cartel
Immediate actions
- Audit all OAuth application authorizations and revoke unrecognized grants
- Block known Coinbase Cartel infrastructure at perimeter (affiliateshinysp1d3r.com, leak site onion)
- Monitor for anomalous bulk API exports from CRM systems (Salesforce, HubSpot)
- Enforce MFA on all administrative and privileged accounts
- Review ESXi host access logs for unauthorized shell script execution
Workarounds
- Disable ESXi Shell and SSH when not actively required for maintenance
- Restrict Tor exit node connectivity at the network perimeter
- Implement allowlisting for OAuth applications in cloud environments
- Enable VMware snapshot integrity monitoring
Longer-term hardening
- Deploy EDR with behavioral detection for in-memory loaders on ESXi hosts
- Implement DLP controls to detect and block large-scale data exfiltration
- Conduct insider threat awareness training focused on bribery and vishing
- Segment VMware infrastructure from general network access
- Implement OAuth token lifetime policies and continuous access evaluation
- Deploy SIEM rules for syslog disablement and mass log truncation detection
Timeline of Coinbase Cartel
- Coinbase Cartel first appeared on the dark web, claiming 14 victims in its inaugural month of operations
- First victim listed on Coinbase Cartel data leak site according to ransomware.live tracking
- Joe Shenouda published first public threat analysis identifying Coinbase Cartel as composite group of ShinyHunters, Scattered Spider, and Lapsus$ affiliates
- Coinbase Cartel announced zero-day acquisition budget exceeding $2 million, signaling advanced operational investment
- Multiple security firms hypothesized potential ShinyHunters connection based on shared infrastructure and contacts (unvalidated)
- Coinbase Cartel breached 10 UAE healthcare organizations in a single month, demonstrating sector-specific targeting capability
- Ranked among Bitdefender Top 10 Ransomware Groups with 60+ victims across 17 industries
- Bitdefender published comprehensive analysis detailing Coinbase Cartel tactics, partnership model, and data-theft-only approach
- Coinbase Cartel victim count reaches 118 according to ransomware.live tracking, with 39.2% infostealer correlation
- Most recent victim listing on Coinbase Cartel data leak site, confirming continued active operations
- FortiGuard publishes threat actor profile confirming active status and documenting shinysp1d3r ESXi ransomware development
- As of 2026-05-29, Coinbase Cartel remains a live, accelerating data-extortion threat — trackers show ~169 victims (updated May 24, 2026) with 3 new listings in a 24h window around May 21 and no takedown, arrest, or sinkholing. The group's data-theft-only model, ShinyHunters/Scattered Spider/Lapsus$ affiliate base, and in-development shinysp1d3r ESXi ransomware confirm ongoing, escalating operations.
Sources cited for Coinbase Cartel
- No Encryptors, No Problem: The Coinbase Cartel Ransomware Group
- Coinbase Cartel Prioritizes Data Theft in Targeted Extortion Campaign
- Coinbase Cartel Ransomware - FortiGuard Threat Actor Profile
- New Threat Actor: Coinbase Cartel - Joe Shenouda
- Threat Intelligence Report September 16-22, 2025 - Red Piranha
- Ransomware.live CoinbaseCartel Tracker
- WatchGuard Coinbase Cartel Ransomware Tracker
- Coinbase Cartel Targets High-Value Sectors with Data-Theft-First Strategy
- Coinbase Cartel Shifts to Data-Theft-First Tactics
- New Cybercriminal Group Targeting Transportation and Logistics Industry
Threats related to Coinbase Cartel
Detection coverage for TL-2026-0319
As of 2026-04-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0319 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.