A previously unknown gang dubbed Triplestrength poses a triple threat to organizations: It infects victims' computers with ransomware, and also hijacks their cloud accounts to illegally mine for cryptocurrency. Google's threat intelligence group has been tracking Triplestrength since 2023, and only recently started talking about this financially motivated criminal crew. It's a small-ish group, "probably focused around a handful of individuals," Genevieve Stark, head of cybercrime, hacktivism, and information operations intelligence analysis for the Google Threat Intelligence Group, told The Register. But, despite lacking in numbers, the gang is very active in hacking and cybercrime forums, and the cloud giant's incident responders have seen online personas connected to Triplestrength advertise access to compromised servers, including those in Google Cloud, Amazon Web Services, Microsoft Azure, Linode, OVHCloud, and Digital Ocean, and recruiting other criminals for its extortion work. On the ransomware front, it appears that the gang's members have carried out attacks since at least 2020, "based on the activity we've seen in underground forums," Stark said. These ransomware infections target on-premises systems only — not cloud infrastructure — and unlike most modern ransomware criminals, they don't involve double-extortion. This is where the thieves first steal victims' files, then encrypt the stolen data, and threaten to leak or sell it if the victim doesn't pay a ransom dem...
Triplestrength hits with ransomware, cloud crypto mining
The Register
·Jessica Lyons
·Published Feb 11, 2025
·Updated
Affected Software
4 affected components
Microsoft Windows
Google Cloud
Amazon Web Services
Microsoft Azure
Frequently Asked Questions
1
What is the main threat posed by the Triplestrength gang?
The Triplestrength gang poses a triple threat through ransomware attacks, cloud account hijacking, and illegal cryptocurrency mining.
2
Which platforms are at risk from the Triplestrength ransomware attack?
Microsoft Windows, Google Cloud, Amazon Web Services, and Microsoft Azure are all affected by the Triplestrength threats.
3
How does the Triplestrength gang exploit cloud accounts?
The gang hijacks cloud accounts to illegally mine cryptocurrency, further draining resources from affected organizations.
4
What security measures can organizations take to protect against Triplestrength?
Organizations should enhance their cybersecurity practices, including regular software updates, strong password policies, and employee training to recognize phishing attempts.
5
Is the Triplestrength group associated with any known cybercriminal organization?
The Triplestrength group is a previously unknown gang, distinguishing itself with its unique triple attack strategy.