logo

VEN0m Ransomware: DFIR Analysis, Detection Engineering & Key Recovery

ID: 5b82851e-761c-50f7-be8b-285b8de735b2

STIX ID: report--5b82851e-761c-50f7-be8b-285b8de735b2

Feed Name: Ransomware ISAC Blog

Threat Score
75/100

Date Published: 2026-02-26

Date Updated: 2026-08-21

Author: [email protected] (Eric Taylor)

...
...

VEN0m is an open-source Rust ransomware proof-of-concept that combines a legitimately signed but vulnerable IObit kernel driver (CVE-2025-26125) with UAC bypass and AES-256-GCM file encryption; the report documents full attack-chain analysis, test detonations (Windows Defender fully bypassed; a commercial EDR prevented the attack by quarantining the driver in ~127 ms), IOCs, 42 behavioral detections, source-code review, and practical key-recovery and IR procedures (the encryption key is hardcoded in the binary).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.