ExfilSquad Quietly Delisted Analog Devices. For a Crew With No Malware and No Exploit, the Leak Site Is the Only Telemetry You Get.
- Patrick Duggan
- 2 hours ago
- 4 min read
Three days ago we published an adversary profile for ExfilSquad, a crew whose defining characteristic is what it does not have: no malware, no exploit, no CVE, no ransomware payload. The entire operation is the bulk harvesting of misconfigured Microsoft Power Pages portals through their own documented interfaces — a public portal, the Anonymous Users web role applied to a table holding real data, and a request. Nothing is broken into. The door was configured open.
Since then a piece of that picture moved, and it moved in a direction worth recording. Analog Devices, which ExfilSquad listed on 26 July with a claim of roughly 570,000 records containing customer personal information and addresses, has been removed from the leak site. Nobody has said why. The conventional reading of a delisting is that negotiations have opened, and that reading is usually right, but it is inference and not fact.
The debut was a portfolio launch, not a start
Here is the detail that reframes this crew, and it comes from lining up two dates that are usually reported separately.
ExfilSquad surfaced publicly on 26 July with fifteen alleged victims already listed — private companies, municipalities, schools, government bodies. Analog Devices says it identified unauthorised access to its systems on 23 June, immediately activated incident response and engaged external experts.
So the access at one named victim predates the leak site's existence by more than a month. A crew does not accumulate fifteen victims across four sectors on its opening day. What happened on 26 July was not the beginning of the operation; it was the marketing launch of an inventory that had been quietly assembled beforehand. The leak site is the pressure mechanism, and it went up only once there was enough leverage to be worth advertising.
That matters operationally. If you are trying to work out whether you were caught in this, the window to examine is not late July. It is the months before it, and for at least one victim that means back to at least mid-June.
Why the delisting is the signal, not a footnote
Most threat actors give you artifacts. A hash, a C2 domain, a loader, a distinctive encryption routine — something you can write a rule against and something that shows up in a feed. ExfilSquad gives you none of that, by design. There is no payload to fingerprint because there is no payload. There is no exploit to detect because nothing was exploited. Their access method is indistinguishable from a legitimate anonymous request to a portal that was configured to allow anonymous requests.
Which leaves a very short list of things that are actually observable from the outside. One is exposure: whether your Power Pages portal has a table reachable by the Anonymous Users role that holds data you would not hand to a stranger. That is checkable today, by you, without any threat intelligence at all, and it is the single highest-value action in this post.
The other is leak-site state. For an encryptor-less crew, publication is the entire weapon. The listing going up, the countdown, the listing coming down — that sequence is the operation's only externally visible behaviour, and it is therefore the only telemetry a defender or a researcher gets. A name appearing tells you leverage was established. A name disappearing tells you the leverage is being converted, most likely into a payment or a negotiation. Tracking that state change is a legitimate intelligence activity precisely because there is nothing else to track.
We are stating that plainly because it cuts against our own commercial interest. We sell a feed of indicators. This actor produces almost none, and we are not going to manufacture some to keep the story tidy.
What we hold, and what we do not
We hold the actor profile, imported 3 August, and it is holding up: the delisting behaviour is consistent with a pure data-theft extortion model, and the Power Pages method described in it remains the mechanism to check your own estate against.
We hold no indicators for the Analog Devices intrusion specifically. There is nothing in our feed a defender can block that is unique to this event, and given the method there may never be, because the method does not generate blockable infrastructure. A feed entry for "an anonymous HTTPS request to your own portal" would be noise.
We also cannot confirm that the Analog Devices intrusion used the Power Pages method at all. It fits the crew's profile, the claim shape matches, and the victim was among the original fifteen — but a semiconductor manufacturer is not an obvious portal-harvesting target, and we have seen no technical detail tying that specific intrusion to that specific method. Treating "same actor" as "same technique" is the kind of shortcut that produces confident, wrong advice. We are flagging the assumption rather than making it.
One correction worth catching before it spreads
At least one widely-syndicated weekly roundup this week ties the Omnicell breach to ExfilSquad. It is not ExfilSquad. Omnicell was listed by Everest, a separate Russian-speaking extortion group we profile independently, on 22 July. Two crews, two victims, two claims, and conflating them will send someone hunting the wrong behaviour in the wrong logs. We wrote about the Omnicell claim separately today.
What to do
If you run Microsoft Power Pages, audit which tables are reachable by the Anonymous Users web role and confirm that none of them expose real customer or citizen data. This costs an afternoon and closes the actual door this crew walks through. It is worth doing whether or not ExfilSquad has ever heard of you, because the misconfiguration is the vulnerability and the crew is interchangeable.
If you have any reason to think you were in the fifteen, examine June and early July rather than late July. The public listing date is when pressure started, not when access did.
We guarantee five percent of what we publish is wrong. On this one the largest uncertainty is stated above and we would rather leave it exposed: we do not know that the Analog Devices intrusion used the method we profiled, and a delisting is a strong inference about negotiations rather than a confirmed fact.
Her name was Renee Nicole Good.
His name was Alex Jeffery Pretti.




Comments