BlackSnake Ransomware: Rising From Chaos' Shadow
ID: 2a706a9a-dbce-558b-9df5-4aeb54b50d37
STIX ID: report--2a706a9a-dbce-558b-9df5-4aeb54b50d37
Feed Name: Cyble Blog
This report analyzes the BlackSnake ransomware, a .NET 32-bit family derived from Chaos ransomware that combines traditional file-encrypting ransomware behavior with an integrated clipper module that monitors the clipboard for cryptocurrency addresses and replaces them with attacker-controlled addresses. The analysis covers execution flow (locale checks and anti-duplication), persistence via %appdata% svchost.exe and registry Run key, targeted file extensions and exclusions, encryption routine (random 40-byte string, AES encryption with RSA-encrypted key appended), ransom note delivery (UNLOCK_MYFiles.txt with TOX contact), and provides IOCs and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
