Sophos reported that two organizations hit by Entropy ransomware were first compromised through intrusions involving Dridex and remote-access tooling such as Cobalt Strike. One attack targeted a North American media company through ProxyShell exploitation and unfolded over roughly four months, while another began with a malicious email attachment sent to a regional government organization and escalated to data exfiltration in about 75 hours. In both cases, the attackers relied on widely available administrative and commercial tools for lateral movement, staging, and theft, including PsExec, PsKill, AdFind, WinRAR, ScreenConnect, and cloud storage services.
Reverse-engineering of the malware found notable similarities between Entropy and Dridex, including shared packer behavior, vectored exception handler setup, string decryption, and API resolution logic. Sophos said the overlap may indicate a development relationship and also noted packer detections previously tied to DoppelPaymer, adding to evidence that Entropy could belong to the ransomware lineage associated with Evil Corp. The findings underscore how unpatched internet-facing systems and weak authentication can enable long-running intrusions that end in ransomware deployment and data theft.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Reverse-engineering by Sophos found similarities between Entropy and Dridex in packer behavior, vectored exception handler setup, string decryption, and API resolution logic, suggesting a possible development relationship.
Sophos analyzed two separate ransomware incidents in which attackers deployed Entropy ransomware after intrusions involving remote-access tooling such as Cobalt Strike and Dridex.
After spending about four months inside the North American media organization probing the network and stealing data, the attackers launched the Entropy ransomware in early December.
About 75 hours after the initial suspicious login detection in the regional government incident, attackers began exfiltrating data after compressing files with WinRAR and uploading archives to privatlab.com, dropmefiles.com, and mega.nz.
In the second incident, a malicious email attachment infected a user's computer at a regional government organization with the Dridex botnet Trojan, which was then used to deliver additional malware and support lateral movement.
In one of the two incidents Sophos investigated, attackers exploited the ProxyShell vulnerability on a North American media organization's Exchange server, installed a remote shell, and used it to spread Cobalt Strike beacons internally.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.