Coinbase Cartel — Data Exfiltration-Only Ransomware Group Targeting Healthcare, Tech & Transportation — Threadlinqs Intelligence
As of 2026-05-30, Coinbase Cartel — Data Exfiltration-Only Ransomware Group Targeting Healthcare, Tech & Transportation is a high-severity ransomware threat attributed to Coinbase Cartel (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-0319 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Coinbase Cartel · Russia · FINANCIAL
Coinbase Cartel is a financially motivated cyber-extortion collective that emerged in September 2025, rapidly accumulating 118+ victims across 17 industries by April 2026. Formed from affiliates of
Coinbase Cartel is a financially motivated extortion collective that first appeared on the dark web in September 2025, claiming 14 victims in its inaugural month. The group is composed of affiliates from well-known threat actor ecosystems including ShinyHunters, Scattered Spider, and Lapsus$, combining their expertise in credential abuse, social engineering, and large-scale data theft.
Unlike traditional ransomware operators, Coinbase Cartel employs a data-theft-first extortion strategy — systematically exfiltrating sensitive data without deploying encryption payloads. This approach makes their intrusions quieter, faster to execute, and significantly harder to detect through conventional ransomware monitoring. Victims are listed on a Tor-hosted data leak site organized into HOME, AUCTIONS, PARTNERSHIPS, and CONTACTS sections, with victim statuses tracked as active, leaking, or leaked.
The group's initial access strategy combines multiple vectors: social engineering campaigns, insider bribery schemes, vishing attacks that trick employees into authorizing malicious OAuth applications, and procurement of access through Initial Access Brokers (IABs). They also acquire exposed credentials and compromise administrative accounts through credential stuffing and reuse attacks.
In cloud environments, Coinbase Cartel leverages custom Python scripts designed to mimic legitimate tools such as the Salesforce Data Loader, enabling mass data exfiltration from CRM systems and cloud APIs without triggering security alerts. For on-premise targets, particularly VMware ESXi infrastructure, the group deploys an in-memory loader called shinysp1d3r that executes via shell scripts on ESXi hosts, retrieving encryptors and launching parallel VMDK encryption while disabling snapshots to hamper recovery efforts. While shinysp1d3r is still under active development as a RaaS offering, its deployment signals an imminent transition to double-extortion capabilities.
Persistence is maintained through long-lived OAuth tokens, creation of hidden accounts, and injection of SSH keys on compromised servers. Defense evasion tactics include disabling syslog forwarding, mass log truncation, and system-wide settings manipulation. The group communicates with victims through a chat interface, providing 48 hours for initial contact and a 10-day deadline for payment negotiation. Payment is accepted exclusively in Bitcoin.
Coinbase Cartel operates a non-RaaS business model but actively recruits partners who can demonstrate evidence of successful compromises, offering flexible compensation through fixed-rate agreements or revenue-sharing models. In October 2025, the group announced a zero-day acquisition budget exceeding $2 million, signaling advanced operational capability and sustained investment in offensive tooling.
By December 2025, Coinbase Cartel ranked among Bitdefender's Top 10 Ransomware Groups. As of April 2026, the group has claimed 118+ victims spanning 17 industries, with Technology (39 victims), Transportation/Logistics (8), Financial Services (8), Manufacturing (8), and Consumer Services (8) representing the most impacted sectors. Geographically, the United States leads with 34 victims, followed by the UAE (12), Germany (9), Canada (6), and France (6). Notably, the group breached 10 UAE healthcare organizations in a single month, demonstrating both the scale and sector-specific focus of their operations. High-profile victims include Illumina, SK Telecom, Staples, JBS Brazil, CEVA Logistics, Kuehne + Nagel, and Dolby Laboratories.
The 39.2% infostealer correlation rate among victims suggests Coinbase Cartel may leverage infostealer-harvested credentials as an initial access vector, further complicating attribution and detection efforts.
Target sectors: healthcare, technology, transportation, financial-services, manufacturing, consumer-services, telecommunications, legal, energy, government, education, media
Target regions: North America, Europe, Middle East, Asia
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1078, T1199, T1566, T1190, T1059, T1059, T1078, T1136, T1098, T1068