Halcyon Identifies New Ransomware Operator Volcano Demon Serving Up LukaLocker
ID: 7e073af8-f245-5701-83c7-207179e36fb7
STIX ID: report--7e073af8-f245-5701-83c7-207179e36fb7
Feed Name: Halcyon Blog
Halcyon researchers report on a new ransomware operator tracked as "Volcano Demon" deploying the LukaLocker encryptor (Windows and Linux variants) in recent attacks: the report details the malware's command-line options, ChaCha8 bulk encryption with Curve25519 ECDH key exchange and footer format, evasion tactics (service/process termination, excluded directories/extensions), IOCs (SHA256 hashes), evidence of data exfiltration for double-extortion, and extortion via direct phone calls to executives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
