Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Groove may have begun as a real breakaway ransomware operation, but a forum poster later claimed the gang was invented to fool the media and security companies. The available reporting does not prove that confession—or settle who was behind Groove. The strongest contemporaneous assessment, from Intel 471, was that a failed attempt to form a real group was more likely than a one-person hoax, while acknowledging that a hoax remained possible.
What the reporting established—and what it did not
In September 2021, researchers from McAfee Enterprise, Intel 471 and Coveware described Groove as an apparent offshoot of Babuk and an operation open to working with associates for financial gain. That was threat-intelligence analysis, not an official attribution or proof of the operators’ identities. In October, a forum user claimed to have fabricated Groove. CyberScoop’s November 2 update said it could not verify that claim.
So “motley crew of disgruntled hackers” and “hoax” are competing interpretations, not a settled either-or verdict. The public record supports the possibility of a real, fluid group as well as the possibility that one person manufactured at least some of its public identity.
How Groove’s story unfolded
June to August 2021: reported ties to Babuk
CyberScoop’s account says that in June, a figure known as Orange created the RAMP forum or site and attacked Babuk publicly, claiming a behind-the-scenes organization called Groove. Researchers later described digital connections between Groove and Babuk, but the reporting did not identify verified individual operators. KrebsOnSecurity reported that Groove was announced on RAMP on August 22.
#1 Best Overall
September 2021: analysts describe an open-collaboration model
On September 8–9, researchers from McAfee Enterprise, Intel 471 and Coveware characterized Groove as an apparent Babuk offshoot willing to collaborate with others for money. Their interpretation fit tensions in the ransomware-as-a-service affiliate model: participants may seek different arrangements or leave one operation to try another. It does not establish how many people actually took part in Groove, or who they were. CyberScoop’s contemporaneous account of the researchers’ assessment is available in its Groove and Babuk report.
October to November 2021: a claimed hoax, then a qualification
In October, a user posting under the handle Boriselcin on the XSS cybercrime forum said he had created a fake Groove gang to manipulate the media and security industry. The post said old Fortinet credentials had been used to attract attention. That is evidence that someone made a confession; it does not authenticate the poster as a Groove operator or demonstrate that every activity associated with Groove was fabricated. KrebsOnSecurity reported the post and chronology in its November 2 account.
Rank #2
CyberScoop added the confession and Intel 471’s response to its story on November 2, 2021, saying it could not verify whether the statement was true or another fabrication. Intel 471 said a single-actor hoax was possible, but considered an unsuccessful attempt to build a real ransomware group more likely. The firm also noted that membership in such groups can be fluid. That is a probability judgment, not confirmation.
Free tools Windows power users keep installed
One-click scans. No signup required.
Why analysts thought Groove could have been real
- Reported digital connections: researchers described links between Groove and Babuk. Those links supported an apparent offshoot theory, but the public reporting did not provide a definitive identity attribution.
- A plausible incentive: recruiting or collaborating with associates for financial gain fits the economics of ransomware operations, where affiliates and operators may have competing interests. Plausibility is not proof that the proposed group existed as described.
- A fluid membership model: as Intel 471 pointed out, membership can change. A group’s instability or inability to recruit successfully would not, by itself, show that it was invented from the start.
The original McAfee analysis page was not available through the cited reporting; the description of its findings here comes from contemporaneous CyberScoop coverage and later reporting by KrebsOnSecurity, rather than a fresh examination of that report.
Rank #3
Why the hoax explanation remained plausible
Groove’s publicity—including dramatic claims about credentials and threats—drew attention from security researchers and journalists. The later forum post offered a straightforward alternative explanation: one person had manufactured a gang persona and used old data to make it look convincing. But a theatrical persona is only a clue, and a confession by an anonymous forum user is not independent proof.
The credential episode also does not settle the question. CyberScoop reported Groove’s claim to have published nearly 500,000 Fortinet VPN login credentials. Fortinet said the data came from systems that had not applied a patch issued in May 2019; its account is titled “Malicious Actor Discloses FortiGate SSL-VPN Credentials.” The reported figure describes the scale of Groove’s claimed dump, not a verified count of active credentials, victims or successful compromises. The data’s age does not prove the gang was fictitious, either.
Rank #4
What remains unknown
- Who controlled every channel or account associated with Groove.
- Whether Boriselcin was an actual operator, an associate, or someone falsely claiming involvement.
- How many people, if any, participated in the operation.
- Whether Groove carried out independently verified ransomware intrusions.
- Whether a real operation used the hoax narrative to obscure or confuse its activity.
The cited 2021 reporting does not provide a conclusive answer to those questions or an authoritative finding identifying Groove’s operators. It should not be read as a current assessment of ransomware activity.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

