Understanding Knight Ransomware: Advisory, Analysis
ID: 296b5ced-17af-5622-a3d5-bec5d1cfeb8d
STIX ID: report--296b5ced-17af-5622-a3d5-bec5d1cfeb8d
Feed Name: CloudSEK Blog
Threat Score
CloudSEK analysts report on Knight (aka Cyclops 2.0), a Golang-based multi-platform ransomware-as-a-service that combines data exfiltration and encryption (ChaCha20+AES256), provides a Tor-hosted affiliate builder/panel and stealer module, assigns per-target domains and automated payment/decryption workflows, and is actively recruiting affiliates while claiming links to other ransomware groups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
