The lifecycle of a ransomware written in Python (featuring KMike)
ID: 0541b86b-6e7a-523c-91f7-1ec4f49fdcb0
STIX ID: report--0541b86b-6e7a-523c-91f7-1ec4f49fdcb0
Feed Name: CloudSEK Blog
Threat Score
This article documents the author-built Python ransomware "KMike," describing its lifecycle—delivery (malicious installer/malware masquerade), sandbox evasion checks, per-file AES-256-CBC encryption with per-file keys wrapped by RSA-2048, use of a Domain Generation Algorithm for command-and-control and unique Bitcoin addresses per victim—and links to the project repository and source code.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
