Group overview
Pure Extraction And Ransom (PEAR) Team is the community of highly responsible and strictly disciplined members. We are a private team and have nothing common with any other threat actors. We've been monitoring this field for a long-long time. So, we understand all the processes and know well how it all works.
Preferred targets
Business Services ยท 12
Healthcare ยท 7
Consumer Services ยท 3
Manufacturing ยท 2
Transportation/Logistics ยท 2
Construction ยท 2
Most targeted countries
US ยท 33
JM ยท 2
CA ยท 2
SG ยท 1
FR ยท 1
NO ยท 1
Tactics & techniques (MITRE ATT&CK)
Initial Access
Valid Accounts
Phishing
Execution
Command and Scripting Interpreter: PowerShell
User Execution: Malicious File
User Execution: Malicious Copy and Paste
Persistence
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Defense Evasion
Obfuscated Files or Information: Encrypted/Encoded File
Process Injection: DLL Injection
Credential Access
Input Capture: Keylogging
Credentials from Password Stores: Credentials from Web Browsers
Collection
Data from Local System
Data Staged
Email Collection
Data from Information Repositories
Archive Collected Data: Archive via Utility
Exfiltration
Exfiltration Over C2 Channel
Exfiltration Over Web Service
Exfiltration Over Webhook
Command and Control
Application Layer Protocol: Web Protocols
Proxy: Multi-hop Proxy