← Back to all threat actors

icefire

IceFire is a ransomware group first observed in 2022 that expanded to Linux in early 2023 by exploiting a vulnerability in IBM Aspera Faspex (CVE-2022-47986), targeting media and entertainment organizations in Turkey, Iran, Pakistan, and the UAE using double-extortion tactics.

How we source and review actor profiles
Motivation
ransomware
Last seen
2022-08-20
Sectors
technology, retail-e-commerce, financial-services, education, manufacturing
Status
Dormant

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

First listed
Victim claim*.algotrader.com listed by icefire

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claim*.bestservers.pro listed by icefire

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claim*.iperactive.com.ar listed by icefire

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claim*.cco1.com listed by icefire

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claim*.vps-vds.com listed by icefire

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claim*.guneshosting.com listed by icefire

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claim*.kodhosting.com listed by icefire

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claim*.kru.ac.th listed by icefire

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claim*.directfn.net listed by icefire

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claim*.feesh.ch listed by icefire

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claim*.skifgroup.com listed by icefire

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Last observed
Indicator2 indicators cataloged

Types: onion.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

icefireCanonical Name

Loading CVEs, techniques, indicators, malware, victims, and activity...