Dark Web Profile: Sinobi Ransomware
ID: 068615d8-1d4e-52da-bfcf-da535b8092f3
STIX ID: report--068615d8-1d4e-52da-bfcf-da535b8092f3
Feed Name: SOCRadar Blog
This report profiles the Sinobi ransomware operation—likely a rebrand/continuation of Lynx and derived from INC source code—detailing its RaaS-like hybrid model, targets (manufacturing, healthcare, finance, education), double-extortion workflow, and full attack lifecycle from initial access (compromised credentials, CVE exploitation, phishing) through privilege escalation, EDR removal, data exfiltration (Rclone), and AES-128-CTR/Curve25519-based encryption. The analysis highlights code similarity metrics, leak site behavior, victim geography, observed TTPs (including disabling defenses and deleting Volume Shadow Copies), and defensive recommendations such as ASM, vulnerability intelligence, and dark web monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
