Threat Actor Profile

Outrider Tiger

Outrider Tiger is a financially motivated cyber threat actor, first identified in June 2023. Known for its development and operation of the Nitrogen loader and LukaLocker ransomware, Outrider Tiger initially operated as an affiliate of the Alphv Ransomware-as-a-Service (RaaS) program until its closure in March 2024.

Threat Actor Profile

Outrider Tiger

Fancy Bear TTPs

Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.

Country of Origin

Outrider Tiger is linked to India, with evidence suggesting state-sponsored motivations tied to intelligence collection.

Members

The exact size of Outrider Tiger is unknown. It is believed to consist of a small, specialized team with expertise in malware development and ransomware deployment.

Leadership

The leadership of Outrider Tiger remains unknown. However, their operations suggest a highly organized structure with access to advanced tools and resources.

Tactics

The group primarily focuses on credential harvesting and targeted intrusions to support intelligence collection.

Techniques

Outrider Tiger employs adversary emulation frameworks like Sliver, Cobalt Strike, and Havoc, alongside custom malware families such as WarHawk and RedThreat.

Procedures

Their methods include phishing campaigns, exploitation of vulnerabilities, and deployment of custom malware to infiltrate and exfiltrate sensitive data.

Want to shut down threats before they start?

Indicators of Compromise (IOCs)

Organizations should monitor for:

  • Known Fancy Bear malware signatures (e.g., XAgent, ADVSTORESHELL).
  • Suspicious domains mimicking government or defense entities.
  • Zero-day exploits in applications like Microsoft Windows and Adobe Flash.
  • Abnormal network traffic patterns indicating command-and-control communications.

Key Victims

Fancy Bear targets include:

  • Governments (United States, Germany, France, Ukraine, and others).
  • Military Organizations (focus on NATO-aligned entities).
  • Media Outlets and Journalists (especially those covering Kremlin-related topics).
  • Critical Infrastructure (energy, aerospace, and defense).
  • International Sporting Organizations (e.g., WADA).
  • Political Groups (e.g., the Democratic National Committee).

Notable Cyber Attacks

Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.

Notable Cyberattacks

The group has been linked to several high-profile breaches, leveraging advanced tools to compromise sensitive systems and exfiltrate data.

Glitch effectGlitch effect

How to Defend Against Outrider Tiger

1

Implement robust phishing defenses.

2

Regularly update and patch systems.

Huntress solutions help protect organizations by monitoring endpoints, detecting intrusions, and mitigating threats with enterprise-grade technology.

Law Enforcement & Arrests

No arrests or law enforcement actions against Outrider Tiger have been reported to date.

References

Related Threat Actor Profiles

Notable developments include the U.S. indictment of GRU-affiliated officers in 2018. Despite these measures, Fancy Bear remains operational, emphasizing the challenges of deterring state-sponsored cyber actors.

Detect, Respond, Protect

See how the global Huntress SOC can augment your team
with 24/7 coverage and unmatched human expertise.
Start your free trial today.

Try Huntress for Free