logo

Demystifying Money Message Ransomware

ID: 044e6200-0889-55f3-86fd-9ac07e14a831

STIX ID: report--044e6200-0889-55f3-86fd-9ac07e14a831

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2023-06-14

Date Updated: 2026-07-17

...
...

Money Message is a recently observed double-extortion ransomware strain (affecting Windows and Linux) that harvests or embeds admin credentials to access and encrypt network shares, uses ECDH key exchange with ChaCha cipher for file encryption, stops backup/services, deletes VSS snapshots, and publishes stolen data on a leak site if ransoms are unpaid; the report includes technical details, hashes (IOCs), and a Yara rule to detect the Windows sample.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.