logo

New Ymir ransomware partners with RustyStealer in attacks

ID: 0ebbfde4-dfca-5260-9200-fcf1c73c44b0

STIX ID: report--0ebbfde4-dfca-5260-9200-fcf1c73c44b0

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-11-11

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Kaspersky and other researchers identified a new Windows ransomware family named Ymir, observed in global attacks since July 2024 following initial access by the RustyStealer infostealer; Ymir runs entirely in memory, uses the ChaCha20 cipher to encrypt files (appending random extensions), drops PDF ransom notes named "INCIDENT_REPORT.pdf", modifies the Windows "legalnoticecaption" to display extortion demands, and removes its executable via PowerShell. The report notes attacker use of credential theft, lateral movement tools (WinRM, PowerShell), additional utilities (Process Hacker, Advanced IP Scanner), and possible external servers for data transfer, though Ymir itself lacks built-in exfiltration and no data-leak site has been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.