216.73.216.6

Two Brands, One Payload as Ransomware Affiliates Drop Identical Code

· Published 23/01/2025 21:03 · Modified 24/01/2025 08:20

Export JSON

Essential information

Published
23/01/2025 21:03
Modified
24/01/2025 08:20
Tags
2025-01-23 hellcat morpheus raas ransomware
Related entities
2 observables, 1 intrusion sets (apt), 8 techniques (mitre), 2 malware, 3 others

Description

Recent months have seen increased activity in new operations, including and . Analysis of payloads from both operations reveals that affiliates are using almost identical code. The samples, uploaded to VirusTotal in December 2024, share similarities in behavior and structure. Both use Windows Cryptographic API for encryption, exclude certain file extensions and folders, and do not alter file extensions after encryption. The ransom notes follow a similar template, with slight differences in contact details. Despite similarities with Underground Team notes, there's insufficient evidence to confirm a direct connection. Understanding shared code across these groups can improve detection efforts and threat intelligence.

External references