adversary tracking

Threat Actors

Actors are scored on demonstrated capability, intent and fit against the Northstar attack surface. Targeting score blends observed campaign evidence with inferred intent.

5 of 5 actors
tracked adversaries

Targeting score against Northstar

ransomware · active since 2023-11

BlackFrost

observed
FROSTBITE-3UNC-2291Winter Ledger

BlackFrost has pivoted from broad MSP intrusion to targeted exploitation of payment-orchestration software. Their affiliate FROSTBITE-3 acquires access from brokers rather than developing initial access in-house, which compresses time-to-exploitation once a PoC lands. Northstar matches every element of their observed target profile: tier-1 US banking, SecurePay stack, high settlement volume.

targeting score
94
momentum 30d
+18
origin
CIS-nexus
motivation
Financial — double extortion with data-leak site
tradecraft

Observed ATT&CK techniques

  • T1190Exploit Public-Facing Application
  • T1078Valid Accounts
  • T1486Data Encrypted for Impact
  • T1567Exfiltration Over Web Service
  • T1199Trusted Relationship
operations

Campaigns

  • CMP-31activeAug–Sep 2026
    FROSTGATE (SecurePay exploitation)
  • CMP-27activeJun 2026 –
    COLD LEDGER (MSP intrusion set)
  • CMP-19dormantQ4 2025
    NORTHWIND (regional banks)
attribution linkage

Predictions attributed to this actor

  • PRD-4417BlackFrost exploitation of CVE-2026-48217 in Northstar payment tier12–18 Sep 202687%
  • PRD-4371Ransomware detonation via managed service provider Aurora ITOct–Nov 202641%