MAFIA ransomware targeting users in Korea
ID: 4b32523a-91d5-5e03-b250-b7602bbd84b1
STIX ID: report--4b32523a-91d5-5e03-b250-b7602bbd84b1
Feed Name: Blaze's Security Blog
This report analyzes the MAFIA ransomware targeting Korean users, detailing its use of OpenSSL-based AES-256-CBC encryption that appends the .MAFIA extension, attempts to stop the South Korean AppCheck anti-ransomware service, and creation of an HTML ransom note. It communicates with C2 via Tor proxies (onion.pet/onion.plus), transmits IV and key values in HTTP GET parameters, and provides multiple sample hashes and domains as IOCs, indicating an active yet somewhat localized criminal ransomware threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
