logo

Shadowroot Ransomware Lures Turkish Victims via Phishing Attacks

ID: 61bd09b2-dbfe-5880-b690-50c8166dc9c4

STIX ID: report--61bd09b2-dbfe-5880-b690-50c8166dc9c4

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-07-16

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

ShadowRoot is a ransomware campaign targeting Turkish businesses that uses phishing emails with PDF invoice attachments to deliver a Delphi binary (RootDesign.exe) hosted on a compromised GitHub account. The malware drops multiple files, creates recursive self-processes that result in repeated encryption and many encrypted file copies, and is described by researchers as rudimentary; defenders are advised to block several identified sender email addresses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.