logo

The Beast Ransomware Hidden in the GUI

ID: 73a88247-de34-5f06-a3a5-e5b6326fc51e

STIX ID: report--73a88247-de34-5f06-a3a5-e5b6326fc51e

Feed Name: ASEC

Threat Score
78/100

Date Published: 2025-10-22

Date Updated: 2026-04-26

Author: ATCP

...
...

Beast is a Ransomware-as-a-Service active since 2025 that publicly lists victims across multiple regions and industries and operates a Tor-based leak site; it spreads via SMB scanning and phishing (often alongside Vidar), enforces region-based execution exclusions, uses ChaCha20 hybrid encryption with embedded public key and 0xA0 metadata that makes decryption effectively infeasible, deletes ShadowCopy, terminates backup/database/AV services, persists via Run key and can be configured via a decrypted .data section; the report includes technical indicators (MD5s, URL) and recommends vulnerability assessments, segmented networks, hardened backups and rapid detection/response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.