logo

Analysis and Attribution of the Eternity Ransomware: Timeline and Emergence of the Eternity Group

ID: 28c72805-284b-5edc-8f9f-ad38e7190734

STIX ID: report--28c72805-284b-5edc-8f9f-ad38e7190734

Feed Name: CloudSEK Blog

Threat Score
78/100

Date Published: 2022-06-03

Date Updated: 2026-04-27

...
...

CloudSEK reports a financially motivated cybercriminal group called "Eternity" that sells worms, stealers, DDoS tools and a ransomware builder. The report includes a technical analysis of an Eternity ransomware sample (C#/.NET) that enumerates local and network drives, encrypts a wide range of file types with AES, protects the symmetric key by encrypting it with RSA and storing it as a Base64 file on the victim desktop, deletes shadow copies via WMI, establishes persistence via Run key, and uses a UI with keyboard hooks; it also provides actor attribution links to a GitHub account L1ghtM4n and related projects (Jester, Vulturi) and includes communication/contact IoCs (Telegram, ProtonMail).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.