adversary tracking
Threat Actors
Actors are scored on demonstrated capability, intent and fit against the Northstar attack surface. Targeting score blends observed campaign evidence with inferred intent.
5 of 5 actors
tracked adversaries
Targeting score against Northstar
ransomware · active since 2023-11
BlackFrost
observed
FROSTBITE-3UNC-2291Winter Ledger
BlackFrost has pivoted from broad MSP intrusion to targeted exploitation of payment-orchestration software. Their affiliate FROSTBITE-3 acquires access from brokers rather than developing initial access in-house, which compresses time-to-exploitation once a PoC lands. Northstar matches every element of their observed target profile: tier-1 US banking, SecurePay stack, high settlement volume.
targeting score
94
momentum 30d
+18
origin
CIS-nexus
motivation
Financial — double extortion with data-leak site
tradecraft
Observed ATT&CK techniques
- T1190Exploit Public-Facing Application
- T1078Valid Accounts
- T1486Data Encrypted for Impact
- T1567Exfiltration Over Web Service
- T1199Trusted Relationship
operations
Campaigns
- CMP-31activeAug–Sep 2026FROSTGATE (SecurePay exploitation)
- CMP-27activeJun 2026 –COLD LEDGER (MSP intrusion set)
- CMP-19dormantQ4 2025NORTHWIND (regional banks)
attribution linkage
Predictions attributed to this actor
- PRD-4417BlackFrost exploitation of CVE-2026-48217 in Northstar payment tier12–18 Sep 202687%
- PRD-4371Ransomware detonation via managed service provider Aurora ITOct–Nov 202641%