Nucleus Software Exports, an Indian lending software provider serving banks and retail lenders, disclosed a ransomware attack that disrupted parts of its internal network and encrypted sensitive business information. The malware was identified as BlackCocaine / EpsilonRed, a newly observed ransomware family, and the company reported the incident to Indian financial regulators and the National Stock Exchange. Nucleus said it does not store customers’ financial data and did not expect any client financial data leakage, while leaving unanswered whether a ransom was paid or exactly how the attackers first gained access.
Research from Sophos tied EpsilonRed to hands-on intrusions that likely began through unpatched Microsoft Exchange servers vulnerable to ProxyLogon. In observed attacks, operators used WMI and a PowerShell orchestrator to spread tooling, create scheduled tasks, delete shadow copies, clear event logs, disable protections, kill processes that could block encryption, and preserve remote access by leaving RDP and Remote Utilities ports open. The final payload, a Go-based Windows binary, broadly encrypted files, appended the .epsilonred extension, and dropped a ransom note; Sophos also linked the group to at least one payment of 4.29 BTC after a successful compromise.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Nucleus Software Exports experienced a ransomware attack that disrupted parts of its internal network and encrypted sensitive business information. The malware used in the incident was identified by the cybersecurity community as BlackCocaine, also known as Epsilon Red.
Sophos published research on a new Go-based ransomware family called Epsilon Red, observed in a hands-on intrusion against a US hospitality business. The report linked the activity to likely exploitation of an unpatched Microsoft Exchange server and detailed the attackers' PowerShell-heavy deployment chain.
Sophos reported that, based on a cryptocurrency address in the ransom note, at least one victim paid 4.29 BTC in ransom, worth about $210,000 at the time.
In a quarterly report filed on Thursday, Nucleus Software said it was containing the damage from the ransomware incident and recovering and restoring affected systems. The company had not confirmed the initial access vector or whether any ransom was paid.
Nucleus Software disclosed the ransomware incident in a filing with the Indian National Stock Exchange. The company said it does not store customers' financial data and told regulators no leakage or loss of client financial data was expected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.