Detect, Respond, Protect
See how the global Huntress SOC can augment your team
with 24/7 coverage and unmatched human expertise.
Start your free trial today.
Outrider Tiger is a financially motivated cyber threat actor, first identified in June 2023. Known for its development and operation of the Nitrogen loader and LukaLocker ransomware, Outrider Tiger initially operated as an affiliate of the Alphv Ransomware-as-a-Service (RaaS) program until its closure in March 2024.
Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.
The group primarily focuses on credential harvesting and targeted intrusions to support intelligence collection.
Outrider Tiger employs adversary emulation frameworks like Sliver, Cobalt Strike, and Havoc, alongside custom malware families such as WarHawk and RedThreat.
Their methods include phishing campaigns, exploitation of vulnerabilities, and deployment of custom malware to infiltrate and exfiltrate sensitive data.
Organizations should monitor for:
Fancy Bear targets include:
Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.
The group has been linked to several high-profile breaches, leveraging advanced tools to compromise sensitive systems and exfiltrate data.
Implement robust phishing defenses.
Regularly update and patch systems.
Huntress solutions help protect organizations by monitoring endpoints, detecting intrusions, and mitigating threats with enterprise-grade technology.
No arrests or law enforcement actions against Outrider Tiger have been reported to date.
Notable developments include the U.S. indictment of GRU-affiliated officers in 2018. Despite these measures, Fancy Bear remains operational, emphasizing the challenges of deterring state-sponsored cyber actors.