logo

Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques

ID: 5fcef2e5-630f-5e40-8975-1e3ec3a931ae

STIX ID: report--5fcef2e5-630f-5e40-8975-1e3ec3a931ae

Feed Name: TrendAI Security Blog

Threat Score
85/100

Date Published: 2026-01-01

Date Updated: 2026-08-14

...
...

Trend Research documents a sophisticated Agenda ransomware campaign that uniquely deployed a Linux ransomware binary on Windows hosts by abusing legitimate remote management tools (WinSCP, Splashtop), enabling execution via WSL, and using BYOVD drivers to disable defenses. The campaign used fake CAPTCHA pages to deliver info-stealers, harvested credentials—particularly from Veeam backup databases—to move laterally and target recovery infrastructure, deployed distributed SOCKS proxy backdoors to obfuscate C2, and demonstrates advanced cross-platform tactics that significantly increase detection and remediation difficulty; the report includes IOC guidance and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.