logo

Getting to the Crux (Ransomware) of the Matter

ID: 8dd24bd3-9f40-5ca6-822c-79a395df2ebc

STIX ID: report--8dd24bd3-9f40-5ca6-822c-79a395df2ebc

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2025-07-18

Date Updated: 2026-04-28

...
...

Huntress describes a previously unpublicized ransomware variant named "Crux" observed in three incidents; actors leveraged valid RDP credentials in at least one case, executed unique unsigned ransomware binaries that spawn svchost.exe -> cmd.exe -> bcdedit.exe to disable system recovery, and dropped ransom notes (crux_readme_[random].txt) referencing BlackByte with support email [email protected]. The report includes IoCs (file hashes, driver C:\Windows\system32\drivers\cfxdlfvk.sys, Defender alert Behavior:Win32/RemoteRegDump.A), evidence of possible data exfiltration via rclone, and recommends monitoring for suspicious svchost.exe and bcdedit.exe activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.