logo

Ransomware Group Demands Nearly $3 Million

ID: 20f42a3d-81ea-5023-9538-947824d23ffc

STIX ID: report--20f42a3d-81ea-5023-9538-947824d23ffc

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2024-10-25

Date Updated: 2026-07-17

...
...

This report documents the discovery and technical analysis of a new ransomware strain called "Underground Team," detailing its 64-bit Visual C/C++ executable (SHA256 provided), use of ShellExecuteW to run commands that delete Volume Shadow Copies and stop MSSQL, volume and file enumeration and selective encryption, dropping of a multi-folder ransom note and a self-deleting CMD cleanup script, and an Onion-based negotiation/ticketing portal; the report includes IOCs, MITRE ATT&CK mappings, and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.