Cronus: Ransomware Threatening Bodily Harm
ID: a98e0a54-9c88-5088-a58f-24e54d78729f
STIX ID: report--a98e0a54-9c88-5088-a58f-24e54d78729f
Feed Name: Pulsedive Blog
This report analyses the Cronus .NET ransomware: it is delivered via a malicious PayPal-themed document that triggers PowerShell to load a Cronus DLL, which establishes persistence by copying to C:\Users\<USERNAME>\AppData\Local and adding a registry Run key, discovers and excludes specific folders/files, terminates targeted processes, and encrypts a wide range of file types (AES-256 CBC; larger files encrypted in three parts) while appending random 5-character extensions; the dropped ransom note demands US$500 in Bitcoin and claims data exfiltration but public telemetry suggests limited observed activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
