New Multi-Platform 01flip Ransomware Supports Multi-platform Architecture, Including Windows and Linux
ID: bdf8d826-6336-589e-b925-94ceab4a588f
STIX ID: report--bdf8d826-6336-589e-b925-94ceab4a588f
Feed Name: cybersecurityNews.com
Palo Alto Networks researchers identified a new Rust‑based ransomware family dubbed 01flip active in mid‑2025, which simultaneously targets Windows and Linux systems (notably in the Asia‑Pacific region and against critical infrastructure). The threat uses AES-128-CBC for file encryption with RSA-2048 protected session keys, deploys Sliver for lateral movement, exploits older internet-facing vulnerabilities (CVE-2019-11580), and implements anti-sandbox and string‑encoding techniques; the Linux sample showed prolonged low detection on VirusTotal, indicating significant evasion capability.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
