This is Spartacus: new ransomware on the block
ID: 7daef14c-1127-523b-9f63-99b78b751e19
STIX ID: report--7daef14c-1127-523b-9f63-99b78b751e19
Feed Name: Blaze's Security Blog
Threat Score
Analysis of the Spartacus ransomware describes its ransom notes and contact emails, appended file extension (.[[email protected]].Spartacus), dropped note (READ ME.txt), deletion of shadow copies via vssadmin, creation of a unique mutex ("Test"), persistence of the ransom window (SetForegroundWindow), and embedded RSA keys; notably, it requires victims to send an ID/public key and suggests decryption may be possible by extracting keys from memory, providing actionable IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
