Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
the Crystal Finance Millennium website was indeed hacked, and serving three different flavors of malware
Both XData and the NotPetya ransomware outbreaks used the update servers of M.E.Doc to deliver their ransomware payloads. It is unclear if this recently discovered ransomware reached users via a trojanized update from the same server or a trojanized M.E.Doc app installed from scratch.
This ransomware tries to pass as another family — WannaCry. The same thing was noticed with XData — based on stolen AES-NI codebase; PSCrypt — based on GlobeImposter; and NotPetya — disguised as Petya.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware mentioned as one of several cyber-attacks affecting Ukraine.
Ransomware targeting users and organizations in Ukraine. It is based on GlobeImposter, encrypts files, appends the .docs extension, drops a ransom note, and uses a batch file to clear Volume Shadow Copies and Event Logs.
A ransomware family based on GlobeImposter. It encrypts files, appends the .pscrypt extension, displays a ransom note demanding payment in bitcoin, removes RDP-related files and registry keys, and clears event logs using wevtutil.
A ransomware campaign aimed at Ukraine that the article says was based on GlobeImposter and was part of the recent cluster of Ukraine-focused ransomware activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.