Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The ransomware creates a Task Scheduler for the " winlogon.exe " file to ensure it is able to execute each time a user logs into the system for persistence.
the malware creates a batch file that contains a code of registry modification to disable the task manager.
The ransomware creates a Task Scheduler for the " winlogon.exe " file to ensure it is able to execute each time a user logs into the system for persistence.
Disguised as svchost.exe The BlackBit ransomware, which was covered in a previous post, disguised itself as a svchost.exe file. Similarly, the recently discovered LokiLocker ransomware was also found disguised as a svchost.exe file.
the malware initiates by retrieving a comprehensive list of all services running on the system.
The ransomware proceeds with the next activity, terminating several processes... The ransomware enumerates all running processes
The malware made POST request communication, with information such as unique-id, disk-size, affiliate username, CPU-name, ram-size, and os-name
The ransomware also generates its ransom note before it begins encrypting.
Once the potentially disruptive services are identified, the malware takes action by stopping the services.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a ransomware family reportedly linked to Proton; no operational details are provided.
A ransomware family reported in the content as linked to Proton and Loki Locker.
Ransomware deployed after brute-force compromise of public-facing RDP. It establishes persistence via Startup folder copies and scheduled tasks, disables Task Manager, stops processes and services, deletes shadow copies and backups, disables firewall and Windows Defender, scans network/SMB shares, communicates with a C2 server, encrypts files with a .BlackBit extension, drops ransom notes, changes wallpaper and logon message, and sets a timer for later drive wiping.
Ransomware presented as highly similar to LokiLocker; it also disguised itself as svchost.exe and used .NET Reactor obfuscation, with similar persistence, ransom note, and post-encryption file icon behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.