From Linear to Complex: An Upgrade in RansomHouse Encryption
ID: 073130e5-d482-5e15-a396-91bb5ec23115
STIX ID: report--073130e5-d482-5e15-a396-91bb5ec23115
Feed Name: Palo Alto Networks Unit 42
Threat Score
This Unit 42 report analyzes the RansomHouse RaaS (attributed to Jolly Scorpius), detailing its operator/affiliate model, the MrAgent deployment/management tool and the Mario encryptor, and a recent upgrade from a single-pass encryption to a two-stage, chunked, multi-key scheme that targets VMware ESXi VM and backup files; the report includes attack-chain TTPs, impact to critical sectors, evidence of active campaigns (≥123 victims listed), and multiple SHA256 IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
