Mad Liberator is a ransomware and extortion threat actor first observed in mid-2024. The group is associated with leak-site operations and appears to emphasize data theft and coercive pressure tactics, with reporting indicating primarily exfiltration-led extortion and some claims of encryption and double-extortion activity. Mad Liberator has been observed abusing legitimate remote-access software, particularly AnyDesk, to obtain interactive access to victim systems through social engineering rather than malware-based initial compromise. In documented intrusions, the actor used unsolicited remote-support requests that victims mistook for legitimate internal IT activity. After access was granted, the operators transferred and executed a fake Windows update-themed decoy program to occupy the user while disabling keyboard and mouse input through remote-access software features. During the same session, they searched accessible data sources, including cloud-synced storage and mapped network shares, and exfiltrated files using built-in file-transfer functionality. The group also conducted local subnet reconnaissance with network scanning tools to identify additional systems of interest, although lateral movement was not confirmed in the observed case. Mad Liberator has also been observed creating ransom notes on shared network locations after data theft and operating a leak site used to pressure victims into payment by threatening publication of stolen information. The actor’s tradecraft blends social engineering, abuse of legitimate administration tools, reconnaissance, exfiltration, and defense-evasion measures intended to reduce user awareness during the intrusion. Known aliases include mad_liberator and mad_liberator_ransomware_group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly emerged ransomware/data-extortion group focused primarily on data exfiltration, with reported occasional encryption and double extortion. In the described incident, it abused AnyDesk remote access, used social engineering to gain session approval, displayed a fake Windows Update screen to mask activity, disabled user input, exfiltrated files from OneDrive and mapped network shares, scanned the subnet with Advanced IP Scanner, and dropped ransom notes on shared network locations.
Observed exploiting AnyDesk for unauthorized remote access by tricking targets into installing the software.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.