Home/Threat Actor/Brain Cipher
Threat Actor

Brain Cipher

brain_cipher · unknown_likely_russia_aligned · active since 2024-06

Brain Cipher is a financially-motivated cybercriminal ransomware operation that emerged publicly in June 2024 via the high-profile attack on the Indonesia National Data Center (Pusat Data Nasional / PDN), June 20, 2024 sovereign-impact ransomware attack disrupting approximately 200+ Indonesian government services for multiple weeks including immigration services at Indonesian airports.

initial $8 million USD ransom demand publicly refused by Indonesian government.

on July 2-3, 2024 Brain Cipher operators released a free decryptor for the PDN attack along with apology messaging (operationally distinctive in ransomware ecosystem, operationally unusual free-decryptor-release pattern)

ransomware binary derived from September 2022 leaked LockBit Black (LockBit 3.0) builder consistent with broader 2023-2024 trend of new ransomware operations bootstrapping on leaked LockBit builder (alongside DragonForce)

operational distinctiveness is the sovereign-government targeting case study and the free- decryptor-with-apology operational behavior rather than sustained high-volume operations.

operationally distinct from and ecosystem-adjacent to all other ransomware clusters curated separately in this corpus including 8base, LockBit, DragonForce, ALPHV/BlackCat.

unknown_likely_russia_aligned confidence: high 9 aliases

Profile

Brain Cipher (Cyfirma canonical naming, June 2024 first- disclosure) is a financially-motivated cybercriminal ransomware operation that emerged publicly in June 2024 with the high-profile attack on the Indonesia National Data Center (Pusat Data Nasional / PDN), an operationally significant sovereign-impact ransomware event that disrupted approximately 200+ Indonesian government services for an extended operational period and stands as one of the most operationally significant sovereign-government-impact ransomware events in the public record. The cluster's operational distinctiveness is concentrated in three dimensions that operationally distinguish Brain Cipher from the broader high-volume ransomware ecosystem: (1) SOVEREIGN GOVERNMENT TARGETING CASE STUDY. The PDN Indonesia June 20, 2024 attack targeted consolidated Indonesian government data infrastructure hosting services for approximately 200+ government agencies and ministries, concentrating ransomware impact into a single facility and dramatically amplifying operational disruption per intrusion compared to per-agency attacks.

The operational impact included immigration services disruption (creating significant operational impact at Indonesian airports), education ministry services disruption, and additional government administration services disruption, sustained for multiple weeks. The case study illustrates the operational impact potential of ransomware attacks against consolidated- government-cloud and shared-data-center architectures, and has been studied in subsequent ransomware policy frameworks including ENISA Threat Landscape Reports and ASEAN-CERT operational advisories. (2) FREE-DECRYPTOR RELEASE WITH APOLOGY MESSAGING.

On July 2-3, 2024, approximately two weeks following the initial PDN attack, Brain Cipher operators publicly released a free decryptor for the PDN Indonesia attack along with an apology message stating regret for the operational impact on Indonesian citizens. The Indonesian government had publicly refused to pay the initial $8 million USD ransom demand. The free-decryptor release was operationally distinctive in the ransomware ecosystem, operationally unusual for ransomware operators to release free decryptors after attacks on non-paying victims.

Industry analysis has speculated about operational rationale including operational reputational concern about civilian-impact backlash, internal cluster operational tension over the sovereign-government targeting decision, or strategic operational positioning. The free- decryptor release stands as a documented operational case study of ransomware operator behavior under reputational and operational pressure following sovereign-impact attacks. (3) LOCKBIT 3.0 BUILDER DERIVATIVE OPERATIONAL POSITIONING.

The Brain Cipher ransomware binary is derived from the September 2022 leaked LockBit Black (LockBit 3.0) builder, consistent with the broader 2023-2024 trend of multiple new ransomware operations bootstrapping on the leaked LockBit builder (DragonForce, curated at dragonforce.yaml, similarly derived from the same leaked builder). The LockBit-derivative positioning operationally distinguishes Brain Cipher from clusters with proprietary encryptor development (LockBit itself, ALPHV/BlackCat, Royal/BlackSuit) and positions Brain Cipher within the broader leaked-builder-derivative ransomware sub-ecosystem. Operational tradecraft includes initial access via compromised credentials and selective N-day vulnerability exploitation, conventional lateral movement (RDP, SMB), data exfiltration to Mega.nz cloud storage via rclone, LockBit-derivative ransomware encryption (with .brain extension and modified ransom notes), VMware ESXi hypervisor targeting variant, and double-extortion pressure via leak-site data publication.

Brain Cipher is curated alongside the broader ransomware ecosystem coverage in this corpus (LockBit, Akira, Play, Black Basta, Royal/BlackSuit, Cactus, Rhysida, INC Ransom, Medusa, Qilin, Hunters International, BianLian, RansomHub, Fog, DragonForce, Interlock, Embargo, NoEscape, Trigona, Hive, REvil, DarkSide/BlackMatter, ALPHV/BlackCat, Maze, Conti/Wizard Spider, Cuba, Vice Society/Vanilla Tempest, 8base). Its operational distinctiveness within this ecosystem is the sovereign-impact PDN Indonesia attack case study and the operationally-unusual free-decryptor release with apology messaging.

Aliases

9
brain_cipherbrain cipherbrain cipher ransomwarebrain cipher operatorslockbit_3_builder_derivative_brain_cipherpdn indonesia attackersindonesia national data center attackersbraincipherbrain-cipher

Notable Campaigns

4
2024-2025Continued Post-PDN Operations and Operational Visibility (2024-2025)
2024Pusat Data Nasional (PDN) Indonesia National Data Center Attack (June 20, 2024)
2024Brain Cipher Operational Emergence and LockBit 3.0 Builder Derivation (June 2024)
2024Brain Cipher Sovereign Government Targeting Significance, Case Study

Attribution & Reporting

Attributed by
CyfirmaSOCRadarBridewell ConsultingSymantec / Broadcom Threat Hunter TeamSophosRecorded FutureTrend MicroIndonesian National Cyber and Crypto Agency (BSSN)Indonesian Ministry of Communications and InformaticsSentinelOneMalaysian CyberSecurity Malaysia (CSM)
Key reporting
reportCyfirma: Brain Cipher Ransomware Analysis (2024), canonical first-disclosure
reportSOCRadar: Brain Cipher Dark Web Profile and PDN Indonesia Attack Analysis
reportBridewell Consulting: Brain Cipher PDN Indonesia Attack 2024, Threat Intelligence Assessment
reportSymantec / Broadcom Threat Hunter Team: Brain Cipher Ransomware Technical Analysis
reportIndonesian National Cyber and Crypto Agency (BSSN): PDN Incident Public Updates and Advisories (June-July 2024)
reportENISA Threat Landscape Report: Sovereign-Impact Ransomware Case Studies (PDN Indonesia coverage)
reportASEAN-CERT Operational Advisory: Sovereign Government Ransomware Preparedness
reportMalpedia Actor Profile: Brain Cipher

Operational

State sponsor

Cybercriminal ransomware operation that emerged publicly in June 2024 with the high-profile attack on the Indonesia National Data Center (Pusat Data Nasional / PDN), an operationally significant sovereign-impact ransomware event that disrupted approximately 200+ Indonesian government services for an extended operational period. The cluster's operational origin is unclear in the public record: industry analysis (Cyfirma, SOCRadar, Bridewell Consulting, Symantec) has not formally attributed Brain Cipher to specific national origin, government affiliation, or established cybercriminal organization. The cluster's operational tradecraft (LockBit Black builder derivative, double-extortion model, ransom negotiation patterns, victim country avoidance consistent with Russian-aligned ecosystem norms) is consistent with the broader Russian-aligned cybercriminal ransomware ecosystem, but no direct evidence linking Brain Cipher to specific named Russian-language criminal forums or affiliates has been publicly disclosed.

The cluster's operational tooling is operationally derived from the September 2022 leaked LockBit Black (LockBit 3.0) builder, operationally consistent with the broader 2023-2024 trend of new ransomware operations bootstrapping on the leaked LockBit builder. The cluster's operational profile is operationally distinguished in the public record primarily by the sovereign-impact PDN Indonesia attack rather than by sustained high-volume operational tempo against many victims. The cluster operates as a financially-motivated cybercriminal operation with no known state sponsorship.

Motivations
financial_gain, ransomware_extortion, double_extortion_data_exfiltration_and_encryption, sovereign_government_targeting, ransom_payment_extraction
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)37/60 · 61%
Runtime / container (Falco)10/60 · 16%
File / malware (YARA)1/60 · 1%
Network (Suricata/Snort)18/60 · 30%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped

CVEs Exploited

2
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin