A Study of Thanos Ransomware Variants
ID: 4c8003ea-3ea3-59de-8d52-07f5254925bf
STIX ID: report--4c8003ea-3ea3-59de-8d52-07f5254925bf
Feed Name: Zscaler Security Research Blog
This ThreatLabz report analyzes Thanos builder–derived ransomware families observed in 2021 (Prometheus, Haron, Spook, Midas), describing their shift to RaaS models and double-extortion via dedicated leak sites. The technical analysis of Midas covers infection behaviors (process and service termination, shadow copy deletion), encryption (Salsa20 per-file keys wrapped with RSA, base64 key appended and FileMarker "GotAllDone"), common ransom notes/extensions, disrupted services/process lists, sandbox detections, and provided IOCs including an MD5 hash.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
