White Paper
THREAT PROFILE: Abyss Ransomware
Abyss is a ransomware group first identified in 2023 that is believed to operate as a private cybercriminal organization. The group uses a double-extortion approach, encrypting victims’ systems while simultaneously stealing sensitive data and threatening to publish it on a dedicated leak site if ransom demands are not met. Abyss has frequently targeted organizations in consumer non-cyclical industries, including healthcare and related sectors where operational disruptions can have significant consequences. This threat profile examines the group’s targeted industries and regions, known exploited vulnerabilities, associated threat actors, attack tools, and behaviors across both Windows and Linux environments. The report also maps Abyss’s tactics, techniques, and procedures to the MITRE ATT&C
