logo

Unveiling Abyss Locker: The Rapid Rise of a Menacing Ransomware Threat

ID: b4d98e4d-8156-5ce9-8b49-40051765cc67

STIX ID: report--b4d98e4d-8156-5ce9-8b49-40051765cc67

Feed Name: Seqrite Blog

Threat Score
80/100

Date Published: 2024-04-11

Date Updated: 2026-04-30

Author: Soumen Burma

...
...

Abyss Locker is a recently observed ransomware operation (linked to HelloKitty) that targets Windows and Linux systems including VMware ESXi via a custom Linux encryptor; the report details its technical behavior — terminating services/processes, deleting shadow copies, creating a mutex, excluding certain files/folders/extensions, using Salsa20 encryption across multiple threads, dropping ransom notes and changing wallpapers — and provides IOCs and MITRE TTP mappings for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.