216.73.217.22

Multi-Platform Ransomware Written in Rust

· Published 10/12/2025 13:06 · Modified 21/12/2025 18:56

Export JSON

Essential information

Published
10/12/2025 13:06
Modified
21/12/2025 18:56
Tags
01flip 2025-12-10 CVE-2019-11580 aes encryption asia-pacific critical-infrastructure data leak multi-platform ransomware rust sliver
Related entities
1 vulnerabilities (cve), 3 observables, 1 intrusion sets (apt), 12 techniques (mitre), 2 malware, 3 others

Description

A new family named , written in , has been observed targeting victims in the region. The malware supports architectures and has been used in attacks on critical infrastructure. Initial access was gained through exploitation of vulnerabilities in internet-facing applications. The encrypts files using AES-128-CBC and RSA-2048, appending the . extension. It employs evasion techniques like using low-level APIs and encoding strings. A possible connection to the LockBit group was noted. The campaign appears to be in early stages, with limited victims so far. Data stolen in the attacks has been offered for sale on dark web forums.

External references