VEN0m Ransomware: DFIR Analysis, Detection Engineering & Key Recovery
ID: 142af842-cb80-5020-9364-2902be51eb53
STIX ID: report--142af842-cb80-5020-9364-2902be51eb53
Feed Name: Ransomware ISAC Blog
VEN0m is an open-source Rust ransomware proof-of-concept that embeds a legitimately signed but vulnerable IObit driver (CVE-2025-26125) to perform kernel-level file deletion (BYOVD), UAC bypass, persistence, and AES-256-GCM encryption; in lab tests it completely bypassed Windows Defender but was halted by a commercial EDR's vulnerable-driver protection within ~127 ms. The report contains full source-code analysis, MITRE mappings, telemetry from multiple detonations, 42 behavioral detection queries for SIEM/EDR, detailed IOCs (hashes, file/registry artifacts, device name and IOCTL), and an IR playbook including a trivial key-recovery method (hardcoded key in the .rdata/persistence binary).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
