BrainCipher

Ransomware
Sourceransomware.live

About the group

Brain Cipher emerged in July 2024. Both Windows and Linux variants are available. Brain Cipher using the leaked build of LockBit Black for their operations. The group suspected to have exploited CVE-2023-28252 (Microsoft Windows CLFS Driver Privilege Escalation Vulnerability). The Ransom demand ranges from $150,000 to $1,00,0000. Demand to be paid with Monero (XMR) cryptocurrency. In 2025, they have shifted their new Negotiation portal to new server with vanity TOR Domain starting with 'brain'.

Exploited vulnerabilities 1

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Impact and victims

The group BrainCipher has 4 known ransomware victims. See the most affected sectors and countries and recent victims.

4known victims
4in Brazil
3sectors hit
Activity (12 months)
06
09
Most attacked sectors
Healthcare2
Manufacturing1
Professional Services1
Most affected countries
🇧🇷 Brasil4
Recent victims
latitudesubro.comManufacturing · BR · 2026-09-29
paipharma.comHealthcare · BR · 2026-06-30
paipharma.comHealthcare · BR · 2026-06-13
Basilio AdvogadosProfessional Services · BR · 2024-10-28

BrainCipher uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →