Ransomware Group Demands Nearly $3 Million
ID: 20f42a3d-81ea-5023-9538-947824d23ffc
STIX ID: report--20f42a3d-81ea-5023-9538-947824d23ffc
Feed Name: Cyble Blog
This report documents the discovery and technical analysis of a new ransomware strain called "Underground Team," detailing its 64-bit Visual C/C++ executable (SHA256 provided), use of ShellExecuteW to run commands that delete Volume Shadow Copies and stop MSSQL, volume and file enumeration and selective encryption, dropping of a multi-folder ransom note and a self-deleting CMD cleanup script, and an Onion-based negotiation/ticketing portal; the report includes IOCs, MITRE ATT&CK mappings, and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
