Unveiling Abyss Locker: The Rapid Rise of a Menacing Ransomware Threat
ID: b4d98e4d-8156-5ce9-8b49-40051765cc67
STIX ID: report--b4d98e4d-8156-5ce9-8b49-40051765cc67
Feed Name: Seqrite Blog
Abyss Locker is a recently observed ransomware operation (linked to HelloKitty) that targets Windows and Linux systems including VMware ESXi via a custom Linux encryptor; the report details its technical behavior — terminating services/processes, deleting shadow copies, creating a mutex, excluding certain files/folders/extensions, using Salsa20 encryption across multiple threads, dropping ransom notes and changing wallpapers — and provides IOCs and MITRE TTP mappings for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
