logo

Everest Ransomware Encryptor Uses ConfuserEx-Protected .NET Binary With Wake-on-LAN Capability

ID: ab18c383-f2c3-5dbb-ad49-563f3865d1b8

STIX ID: report--ab18c383-f2c3-5dbb-ad49-563f3865d1b8

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-07-09

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

This report provides a technical analysis of an Everest ransomware .NET 4.0 encryptor (C# sample) protected by ConfuserEx, highlighting heavy obfuscation, ~210 runtime string-decryption routines, and misleading cryptographic declarations that effectively downgrade to RSA-1024 and AES-128 with an insecure Rfc2898DeriveBytes key derivation. The binary performs geofencing, anti-analysis (mutex, anti-debugging, anti-Raccine, Restart Manager misuse), disables security/backup services, deletes backups/volume shadow copies, applies DACL self-protection, assigns drive letters and enumerates UNC paths, uses Wake-on-LAN to wake hosts before lateral movement, partially or fully encrypts files (shredding small files), drops a ransom note, and schedules self-deletion; AttackIQ and RansomLook are cited for emulation and IOC/contextual detail.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.