Sugar Ransomware
ID: 4edea1ac-09b6-50fa-9097-26c7dd600c48
STIX ID: report--4edea1ac-09b6-50fa-9097-26c7dd600c48
Feed Name: Cyble Blog
This report analyzes the "Sugar" (Encoded01) ransomware, a low-profile RaaS targeting small businesses and individuals. The authors describe a 32-bit loader that decrypts and loads a Delphi payload in memory, enumerate API usage and multi-threading anti-analysis tactics, list network calls used for geolocation and a downloaded .dat file, show the ransomware appends the extension "encoded01" and drops a BackFiles_encoded01.txt ransom note, and document a Tor leak/negotiation site that offers low ransom demands. The report includes MITRE ATT&CK mappings, multiple SHA-256 IoCs, and a Yara rule, plus general mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
