New NonEuclid RAT Evades Antivirus and Encrypts Critical Files
ID: b422721f-a912-571b-83af-835165f0f4b8
STIX ID: report--b422721f-a912-571b-83af-835165f0f4b8
Feed Name: GBHackers
NonEuclid is a sophisticated C# Remote Access Trojan for .NET Framework 4.8 that combines advanced evasion (AV bypass, anti-VM, rootkit-like hiding), persistence (scheduled tasks, registry/service manipulation), privilege escalation (UAC bypass), credential and cryptocurrency wallet theft, and integrated ransomware that encrypts files (appending ".NonEuclid"). It is distributed via social media, underground forums, and phishing, supports remote control and lateral movement, and is increasingly observed in criminal marketplaces; mitigation recommendations include EDR deployment, threat intelligence sharing, strict privilege management, patching, and user awareness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
