Limba is a ransomware variant associated with the Proton ransomware family, alongside Zola and Shinra. It has been reported as targeting Chinese-speaking victims. Its relationship to the Proton lineage does not by itself establish the identity, nationality, or location of its operators.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Proton-family ransomware strain reportedly targeting Chinese-speaking victims.
A Proton-family ransomware strain reported to target Chinese-speaking victims.
A Proton-family ransomware variant reportedly targeting Chinese victims. The report assesses its relationship with Zola and Shinra as likely arising from shared authorship or source-code delegation.
Ransomware variant linked in the content to the Proton family and associated with targeting Chinese victims.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.