ColdLock Ransomware Hits Taiwanese Organizations
ID: 15af7c8e-5117-51ab-bbbc-000e5370f34d
STIX ID: report--15af7c8e-5117-51ab-bbbc-000e5370f34d
Feed Name: Cyble Blog
Cyble reports a new ransomware family named ColdLock active since May 2020 that has infected several Taiwanese organizations, including a major mining company. ColdLock is delivered as a ConfuserEx-protected .NET DLL executed via PowerShell reflective loading, targets databases and email servers for encryption, performs environment checks (presence of %SystemRoot%\ProgramData\readme.tmp and a time-of-day check), terminates services that block file access, and executes Windows 10-specific routines to disable Defender and reporting; researchers note code and behavioral overlaps with EDA2, LockerGoga and Freezing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
