Trend Micro reported that the Rapture ransomware family was used in intrusions that likely began with exploitation of vulnerable public-facing web servers, with activity often originating from w3wp.exe. Operators carried out reconnaissance, deployed Cobalt Strike through PowerShell fetched from a command-and-control server, and abused explorer.exe with the /NOUACCHECK flag to gain elevated execution while keeping the intrusion chain relatively small and difficult to detect.
Researchers said Rapture shares some traits with Paradise ransomware, including its RSA key configuration style and .NET execution requirements, but differs in behavior and only loosely resembles Zeppelin in its ransom note. The malware was commonly executed in memory instead of being written to disk, was packed with Themida to complicate analysis, and used hard-coded six-character strings in both ransom notes and encrypted filenames; observed attacks typically unfolded over three to five days.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Trend Micro researchers observed a ransomware family they named Rapture operating in March and April 2023. They assessed that the family had likely existed before this reporting, but no samples were available during its initial sighting.
Trend Micro published a technical analysis describing Rapture's intrusion chain, including likely initial access via vulnerable public-facing web servers, Cobalt Strike deployment through PowerShell, privilege escalation via explorer.exe /NOUACCHECK, and ransomware execution largely in memory. The report also noted similarities to Paradise ransomware in RSA key configuration and .NET requirements.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.