50 Shades of Ransomware
ID: 0e662200-50e2-51b0-bbad-2433ca9f77ac
STIX ID: report--0e662200-50e2-51b0-bbad-2433ca9f77ac
Feed Name: Group-IB Blog
This report analyzes the Shade (Troldesh) ransomware family: it details infection via spearphishing with weaponized JS attachments, execution and masquerading behavior (wscript.exe and a JPG-named loader), persistence using Registry Run keys, and dual impact—file encryption (ransomware) and ZCash cryptomining—while extracting forensic artifacts (Jump Lists, WebCacheV01.dat, prefetch, NTUSER.DAT, and malicious scripts) and mapping the observed techniques to MITRE ATT&CK (T1193, T1204, T1064, T1036, T1060, T1486, T1496).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
