REvil Ransomware Uses DLL Sideloading
ID: bacd4cf7-e619-5601-8335-f24e0574aeff
STIX ID: report--bacd4cf7-e619-5601-8335-f24e0574aeff
Feed Name: McAfee Labs Blog
Threat Score
This McAfee analysis details the REvil/Sodinokibi ransomware campaign, including DLL side‑loading via a signed Microsoft binary, RC4/Salsa20-based payload and encryption, localization checks to avoid certain countries, termination of wide-ranging applications and services, evidence of exploitation through CVE-2019-2725 and Kaseya VSA, and provided IOCs and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
