Kasseika ransomware uses antivirus driver to kill other antiviruses
ID: 170d4599-1056-590f-bd2f-f962ffd19ea9
STIX ID: report--170d4599-1056-590f-bd2f-f962ffd19ea9
Feed Name: Bleeping Computer
Threat Score
Kasseika is a newly identified ransomware campaign that uses a signed vulnerable driver (Martini.sys) in BYOVD attacks to disable antivirus, spreads via credential theft and PsExec lateral movement, encrypts files with ChaCha20/RSA, and extorts victims with a 50 BTC ransom demand; Trend Micro published the technical analysis and IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
