Getting to the Crux (Ransomware) of the Matter
ID: 8dd24bd3-9f40-5ca6-822c-79a395df2ebc
STIX ID: report--8dd24bd3-9f40-5ca6-822c-79a395df2ebc
Feed Name: Huntress Blog
Huntress describes a previously unpublicized ransomware variant named "Crux" observed in three incidents; actors leveraged valid RDP credentials in at least one case, executed unique unsigned ransomware binaries that spawn svchost.exe -> cmd.exe -> bcdedit.exe to disable system recovery, and dropped ransom notes (crux_readme_[random].txt) referencing BlackByte with support email [email protected]. The report includes IoCs (file hashes, driver C:\Windows\system32\drivers\cfxdlfvk.sys, Defender alert Behavior:Win32/RemoteRegDump.A), evidence of possible data exfiltration via rclone, and recommends monitoring for suspicious svchost.exe and bcdedit.exe activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
