Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 18:12:42 UTC Home > List all groups > List all tools > List all groups using tool RansomBoggs Tool: RansomBoggs Names RansomBoggs Category Malware Type Ransomware Description (ESET) The ESET research team has spotted a new wave of ransomware attacks taking aim at multiple organizations in Ukraine and bearing the hallmarks of other campaigns previously unleashed by the Sandworm APT group. Even though the ransomware – called RansomBoggs by ESET and written in the .NET framework – is new, particularly the way it is deployed bears close resemblance to some past attacks attributed to the notorious threat actor. Information Last change to this tool card: 27 December 2022 Download this tool card in JSON format All groups using tool RansomBoggs Changed Name Country Observed APT groups Sandworm Team, Iron Viking, Voodoo Bear 2009-Dec 2024 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=fece3a9e-5d1f-4a19-9eb5-519c3fe3d9c2 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=fece3a9e-5d1f-4a19-9eb5-519c3fe3d9c2 Page 1 of 1