AtomSilo Ransomware Enters the League of Double Extortion
ID: 58ad5b6f-a692-56e7-a414-69e61e03ac68
STIX ID: report--58ad5b6f-a692-56e7-a414-69e61e03ac68
Feed Name: Zscaler Security Research Blog
AtomSilo is a double-extortion ransomware group active since ~September 2021; this report provides a technical analysis of their intrusion vector (Confluence exploit and DLL side-loading), post-exploitation techniques (WMI execution, use of admin accounts), encryption mechanics (XOR + AES with AESKEYGENASSIST, chunked encryption, .atomsilo file extension), exclusions/ransom note behavior, and leak-site operations including a published ~900 GB dataset and at least one MD5 IOC.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
