logo

Sage 2.0 analysis

ID: 24bd74c1-ed7a-554c-9e9d-0d4e70db4451

STIX ID: report--24bd74c1-ed7a-554c-9e9d-0d4e70db4451

Feed Name: CERT Polska

Threat Score
75/100

Date Published: 2017-02-14

Date Updated: 2026-04-19

Author: Jarosław Jedynak

...
...

*Sage 2.0 is a CryLocker-derived ransomware distributed via malspam (ZIP attachments containing macro-enabled Word documents) that performs locale and location fingerprinting, requires UAC approval, persists in %APPDATA% and re-encrypts files after reboot; it uses Curve25519 ECDH with ChaCha for per-file encryption, appends encrypted key material to files, provides a Tor-based ransom panel, and the report includes YARA rules and multiple SHA-256 sample hashes.*

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.