YourCyanide: An Investigation into ‘The Frankenstein’ Ransomware that Sends Malware Laced Love Letters
ID: fe422e13-90d1-52e0-8a7c-383eb03c20ad
STIX ID: report--fe422e13-90d1-52e0-8a7c-383eb03c20ad
Feed Name: CloudSEK Blog
CloudSEK researchers detail the YourCyanide ransomware: a CMD/batch-based, multi-stage strain distributed via Discord attachments and Pastebin that downloads a dropper (YourCyanide.exe) which fetches heavily obfuscated batch ransomware and a C# Discord token stealer (GetToken.exe). The malware achieves persistence via Run registry keys and Startup, terminates security services and common processes, encrypts user data with a .cyn extension, steals system and application data (including Discord tokens and Minecraft files), exfiltrates information to a Telegram bot, and includes IoCs and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
