The Beast Ransomware Hidden in the GUI
ID: 73a88247-de34-5f06-a3a5-e5b6326fc51e
STIX ID: report--73a88247-de34-5f06-a3a5-e5b6326fc51e
Feed Name: ASEC
Beast is a Ransomware-as-a-Service active since 2025 that publicly lists victims across multiple regions and industries and operates a Tor-based leak site; it spreads via SMB scanning and phishing (often alongside Vidar), enforces region-based execution exclusions, uses ChaCha20 hybrid encryption with embedded public key and 0xA0 metadata that makes decryption effectively infeasible, deletes ShadowCopy, terminates backup/database/AV services, persists via Run key and can be configured via a decrypted .data section; the report includes technical indicators (MD5s, URL) and recommends vulnerability assessments, segmented networks, hardened backups and rapid detection/response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
