Mole ransomware: analysis and decryptor
ID: 269396ac-2679-5af5-9c25-db6160dd5a3f
STIX ID: report--269396ac-2679-5af5-9c25-db6160dd5a3f
Feed Name: CERT Polska
Threat Score
This report analyzes the Mole ransomware (a CryptoMix-family variant) that is distributed via malspam linking to fake Word documents which prompt a malicious plugin; it details persistence mechanisms, a UAC bypass trick, shadow copy deletion, obfuscated target extensions, and an RC4-based encryption routine, and includes hashes/patterns and a note that victims sought a decryptor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
