logo

Ziggo ransomware phishing campaign still increasing in size

ID: 71a2efa0-bb0d-586c-b361-86a37d9c14c5

STIX ID: report--71a2efa0-bb0d-586c-b361-86a37d9c14c5

Feed Name: Fox-IT blog

Threat Score
75/100

Date Published: 2016-10-20

Date Updated: 2026-04-27

...
...

Fox-IT SOC observed an active TorrentLocker ransomware campaign (October 2016) distributing via fake Ziggo invoice phishing e-mails that lead victims to download a ZIP containing JavaScript which downloads the ransomware; infected systems have files encrypted with a ".enc" extension. The report provides IoCs (malicious domains, an IP, SSL certificate details), notes that the malware steals address books to expand propagation, and describes network behavior (initial SSL C2 then Tor) and ongoing takedown/mitigation efforts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.