Technical Analysis of BlueSky Ransomware
ID: 0116ef1f-6016-5de7-9700-5738020e6ef3
STIX ID: report--0116ef1f-6016-5de7-9700-5738020e6ef3
Feed Name: CloudSEK Blog
Threat Score
This report is a technical deep-dive into BlueSky ransomware (first observed June 2022), detailing its initialisation, privilege escalation, mutex and string-decoding mechanisms, targeted file extensions and directories, registry persistence and recovery blob storage, process-killing behavior, IO completion port-based multithreaded encryption (writing ".bluesky" extensions), ransom note generation, and post-encryption cleanup; it also supplies MD5 IoCs and example ransom notes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
