Money Message is a ransomware operation first publicly identified in March 2023. It is known to run a leak site and to conduct double-extortion attacks that combine data theft with encryption pressure. The group has been linked to intrusions and victim claims across multiple sectors, including health care, transportation, energy, and nonprofit organizations, with observed victims in the United States and Canada. Publicly reported incidents attributed to the group include the 2023 PharMerica and BrightSpring Health Services breach, in which the actor claimed large-scale data exfiltration and subsequently leaked patient-related information, as well as later victim postings involving transportation, energy, and services organizations. Operational reporting indicates the ransomware is written in C++ and uses Elliptic Curve Diffie-Hellman key exchange together with the ChaCha stream cipher. In observed intrusions, attackers associated with Money Message staged the encryptor for deployment across multiple hosts and used PowerShell to remove or disable security tooling, including endpoint detection and response products. Incident-response reporting also assessed with moderate confidence that Money Message was involved in pre-ransomware activity in at least one 2026 case that was contained before encryption occurred, indicating the group’s activity can include intrusion and staging phases prior to full ransomware deployment. Money Message should be tracked as a financially motivated cybercriminal ransomware actor rather than a nation-state threat group. Known naming variants include Money Message and money_message.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against Yourway Transportation.
Conducting a ransomware attack against Indigo Energy.
Conducting a ransomware attack against Envision Unlimited.
Conducting a ransomware attack resulting in a data breach against X-Copper Professional.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.