Dark 101 Ransomware Leverages .NET Binary to Disable Recovery Features
ID: 0228f6f8-901d-5ebd-afe0-9c0f4e239add
STIX ID: report--0228f6f8-901d-5ebd-afe0-9c0f4e239add
Feed Name: Halcyon Blog
Dark 101 is a newly observed ransomware strain that evades analysis, copies itself to %Appdata% as a trusted-looking svchost.exe, disables recovery mechanisms (vssadmin/wmic/wbadmin commands), alters registry settings to block Task Manager, uses mutexes and selective targeting, and encrypts user files appending random four-character extensions; the report also notes exploitation of backup solutions like Veeam for escalation and lateral movement and emphasizes the need for early detection rather than relying solely on backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
