WastedLocker: A New Ransomware Variant Developed By The Evil Corp Group
ID: a1d22c43-a672-58cf-87bf-d5a5356f8b6e
STIX ID: report--a1d22c43-a672-58cf-87bf-d5a5356f8b6e
Feed Name: Fox-IT blog
Threat Score
This technical report by Fox-IT/NCC Group analyzes WastedLocker, a targeted ransomware variant linked to Evil Corp active since May 2020, detailing attribution, distribution via the SocGholish fake-update framework, custom CobaltStrike loaders and the CryptOne crypter, UAC bypass and privilege escalation techniques, file-encryption and exclusion behaviors, and providing extensive IoCs (domains, sample hashes, beacon configs) and a decrypter reference to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
