216.73.216.233

Underground Ransomware Being Distributed Worldwide

· Published 27/08/2025 16:22 · Modified 27/08/2025 19:43

Export JSON

Essential information

Published
27/08/2025 16:22
Modified
27/08/2025 19:43
Tags
2025-08-27 data theft encryption global attacks ransomware striping method underground ransomware
Related entities
1 intrusion sets (apt), 11 techniques (mitre), 1 malware, 13 others

Description

The gang is conducting against companies across various countries and industries. First identified in July 2023, the group resurfaced in May 2024 with a new Dedicated Leak Site. Their targets include multinational corporations from diverse sectors, with annual revenues ranging from $20 million to $650 million. The uses a combination of RNG, AES, and RSA techniques, with each file encrypted using a different AES key. The malware is designed to leave insufficient traces for decryption in the local environment. It categorizes files based on size and employs a for larger files. The also deletes shadow copies, restricts remote desktop connections, and stops interfering services before .

External references