A Mole exposing itself to sunlight
ID: 42b8656e-8abf-527b-aaa1-3b31c62abfee
STIX ID: report--42b8656e-8abf-527b-aaa1-3b31c62abfee
Feed Name: Fox-IT blog
Fox-IT observed an active ransomware campaign named "Mole" spread via a social-engineering exploit kit that lures users to install a malicious Office "plugin"; upon execution it terminates processes, removes Windows backups, encrypts files with a .MOLE extension (RSA-1024), and displays a ransom note. The report provides infection statistics (500+ infections, many unique IPs suggesting targeted organizations), multiple IoCs (two binary hashes, several download hostnames, and a C2 IP), and ransom contact addresses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
