Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques
ID: 5fcef2e5-630f-5e40-8975-1e3ec3a931ae
STIX ID: report--5fcef2e5-630f-5e40-8975-1e3ec3a931ae
Feed Name: TrendAI Security Blog
Trend Research documents a sophisticated Agenda ransomware campaign that uniquely deployed a Linux ransomware binary on Windows hosts by abusing legitimate remote management tools (WinSCP, Splashtop), enabling execution via WSL, and using BYOVD drivers to disable defenses. The campaign used fake CAPTCHA pages to deliver info-stealers, harvested credentials—particularly from Veeam backup databases—to move laterally and target recovery infrastructure, deployed distributed SOCKS proxy backdoors to obfuscate C2, and demonstrates advanced cross-platform tactics that significantly increase detection and remediation difficulty; the report includes IOC guidance and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
