logo

Mole ransomware: analysis and decryptor

ID: 269396ac-2679-5af5-9c25-db6160dd5a3f

STIX ID: report--269396ac-2679-5af5-9c25-db6160dd5a3f

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2017-05-30

Date Updated: 2026-04-19

Author: Jarosław Jedynak

...
...

This report analyzes the Mole ransomware (a CryptoMix-family variant) that is distributed via malspam linking to fake Word documents which prompt a malicious plugin; it details persistence mechanisms, a UAC bypass trick, shadow copy deletion, obfuscated target extensions, and an RC4-based encryption routine, and includes hashes/patterns and a note that victims sought a decryptor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.