logo

VEN0m Ransomware: DFIR Analysis, Detection Engineering & Key Recovery

ID: 142af842-cb80-5020-9364-2902be51eb53

STIX ID: report--142af842-cb80-5020-9364-2902be51eb53

Feed Name: Ransomware ISAC Blog

Threat Score
78/100

Date Published: 2026-02-26

Date Updated: 2026-07-19

Author: [email protected] (Eric Taylor)

...
...

VEN0m is an open-source Rust ransomware proof-of-concept that embeds a legitimately signed but vulnerable IObit driver (CVE-2025-26125) to perform kernel-level file deletion (BYOVD), UAC bypass, persistence, and AES-256-GCM encryption; in lab tests it completely bypassed Windows Defender but was halted by a commercial EDR's vulnerable-driver protection within ~127 ms. The report contains full source-code analysis, MITRE mappings, telemetry from multiple detonations, 42 behavioral detection queries for SIEM/EDR, detailed IOCs (hashes, file/registry artifacts, device name and IOCTL), and an IR playbook including a trivial key-recovery method (hardcoded key in the .rdata/persistence binary).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.