A new ransomware family named 01flip has emerged, targeting critical infrastructure organizations in the Asia-Pacific region, specifically in countries such as the Philippines and Taiwan. This ransomware is notable for being fully written in the Rust programming language, enabling it to infect both Windows and Linux systems through cross-compilation. Researchers from Unit 42 at Palo Alto Networks have tracked this activity under the cluster identifier CL-CRI-1036, observing that the attackers employ a hands-on approach, manually exploiting vulnerabilities like CVE-2019-11580 to gain initial access. Once inside, the threat actors deploy the open-source Sliver C2 framework to maintain persistence and facilitate lateral movement within compromised networks.
The campaign, first detected in June 2025, has already resulted in confirmed data leaks, with stolen information being offered for sale on dark web forums. The attackers are financially motivated and have demonstrated a preference for targeted, rather than opportunistic, attacks. Security researchers emphasize the sophistication of 01flip, highlighting its multi-platform capabilities and the use of advanced adversary emulation tools. Organizations in the APAC region are advised to remain vigilant, as the campaign appears to be in its early stages but poses a significant threat to critical infrastructure sectors.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
In June 2025, Unit 42 publicly reported the newly observed Rust-based, multi-platform ransomware family 01flip and tracked the activity cluster as CL-CRI-1036 targeting a limited number of APAC victims.
Following ransomware deployment, the attackers demanded 1 BTC for decryption and an alleged victim data leak was posted on a dark web forum, although researchers could not fully verify the leak's legitimacy.
By late May 2025, the CL-CRI-1036 operators distributed multiple 01flip ransomware instances across both Windows and Linux devices in a small number of APAC victim environments, including targets in the Philippines and Taiwan.
After gaining access, the operators deployed a Linux Sliver implant and later used a Sliver TCP pivot to support persistence and lateral movement in targeted Asia-Pacific environments.
Investigators observed exploitation attempts against older vulnerabilities, including CVE-2019-11580, beginning in early April 2025 as the initial access stage of the 01flip intrusion activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.