Demystifying Money Message Ransomware
ID: 044e6200-0889-55f3-86fd-9ac07e14a831
STIX ID: report--044e6200-0889-55f3-86fd-9ac07e14a831
Feed Name: Cyble Blog
Threat Score
Money Message is a recently observed double-extortion ransomware strain (affecting Windows and Linux) that harvests or embeds admin credentials to access and encrypt network shares, uses ECDH key exchange with ChaCha cipher for file encryption, stops backup/services, deletes VSS snapshots, and publishes stolen data on a leak site if ransoms are unpaid; the report includes technical details, hashes (IOCs), and a Yara rule to detect the Windows sample.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
