Sarcoma Ransomware Unveiled: Anatomy of a Double Extortion Gang
Essential information
- Published
- 20/05/2025 19:18
- Modified
- 21/05/2025 21:52
- Tags
- 2025-05-20 chacha20 encryption hypervisor linux network-propagation rsa sarcoma ransomware windows
- Related entities
- 2 observables, 1 intrusion sets (apt), 12 techniques (mitre), 7 others
Description
Sarcoma Ransomware, first detected in October 2024, has rapidly become a major cybersecurity threat, targeting high-value companies across industries. It uses advanced tactics like zero-day exploits and RMM tools for network discovery and credential theft. The group has impacted organizations in various countries, with the USA, Italy, and Canada being the most affected. Sarcoma employs sophisticated encryption techniques, combining RSA and ChaCha20, and has versions for both Windows and Linux systems. The malware includes network propagation capabilities and anti-recovery measures for hypervisor systems. Notably, it avoids infecting systems with Uzbek keyboard layouts, suggesting possible origins or affiliations. The group's activities highlight the need for improved cybersecurity measures in organizations worldwide.