LockCrypt Ransomware
ID: ecafeba2-16c9-57e8-989d-0e864b4fa932
STIX ID: report--ecafeba2-16c9-57e8-989d-0e864b4fa932
Feed Name: Binary Defense Blog
Attackers have been conducting RDP brute-force attacks since June to deploy a ransomware variant called "LockCrypt" that encrypts files (appending ".lock"), deletes backups, persists on infected servers, and exfiltrates base64-encoded machine data to a server in Iran; victims in the US, UK, South Africa, India, and the Philippines were asked to pay 0.5–1 BTC per server, with reported payments, and recommended mitigations include enforcing strong passwords, enabling two-factor authentication, and restricting RDP exposure to the internet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
