Ransomware Tracker (Entry #213): BlackSkull
ID: f5a0b289-f402-5a33-bf43-541eaa9549ad
STIX ID: report--f5a0b289-f402-5a33-bf43-541eaa9549ad
Feed Name: WatchGuard Secplicity Blog
Threat Score
BlackSkull is a low-impact, likely test ransomware built from the NoCry/WannaCry builder and related to GhosHacker, Anonymous, and possibly early AzzaSec. Only one sample has been observed; it changes the desktop wallpaper, drops two ransom notes (HTML and a process-driven message), appends the .BlackSkull extension to files encrypted with AES, and demands $200—overall assessed as having minimal threat due to limited sightings and likely test status.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
