216.73.217.22

Getting to the Crux (Ransomware) of the Matter

· Published 21/07/2025 08:15 · Modified 21/07/2025 08:57

Export JSON

Essential information

Published
21/07/2025 08:15
Modified
21/07/2025 08:57
Tags
2025-07-21 bcdedit crux data exfiltration process injection ransomware rclone rdp svchost
Related entities
3 observables, 1 intrusion sets (apt), 10 techniques (mitre), 1 malware

Description

A new variant named has been identified, claiming association with the BlackByte group. Observed in three separate incidents, encrypts files with a . extension and leaves ransom notes. Initial access appears to involve Remote Desktop Protocol () using valid credentials. The executable, with varying names and locations, follows a distinct process tree involving .exe, cmd.exe, and .exe. It disables system recovery to hinder restoration attempts. using was observed in one incident. The threat actor demonstrates prior knowledge of targeted infrastructures and prefers using legitimate Windows processes. While claiming BlackByte affiliation, this hasn't been independently verified.

External references