Multi-Platform Ransomware Written in Rust
Essential information
- Published
- 10/12/2025 13:06
- Modified
- 21/12/2025 18:56
- Tags
- 01flip 2025-12-10 CVE-2019-11580 aes encryption asia-pacific critical-infrastructure data leak multi-platform ransomware rust sliver
- Related entities
- 1 vulnerabilities (cve), 3 observables, 1 intrusion sets (apt), 12 techniques (mitre), 2 malware, 3 others
Description
A new ransomware family named 01flip, written in Rust, has been observed targeting victims in the Asia-Pacific region. The malware supports multi-platform architectures and has been used in attacks on critical infrastructure. Initial access was gained through exploitation of vulnerabilities in internet-facing applications. The ransomware encrypts files using AES-128-CBC and RSA-2048, appending the .01flip extension. It employs evasion techniques like using low-level APIs and encoding strings. A possible connection to the LockBit group was noted. The campaign appears to be in early stages, with limited victims so far. Data stolen in the attacks has been offered for sale on dark web forums.