logo

Bl00dy – New Ransomware Strain Active in the Wild

ID: 6f7e137f-1ca5-5c05-8720-88f2fb385981

STIX ID: report--6f7e137f-1ca5-5c05-8720-88f2fb385981

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2022-09-29

Date Updated: 2026-07-20

...
...

Bl00dy is a newly observed ransomware family performing double-extortion attacks: it encrypts files (appending .bl00dy), drops ransom notes, and publishes stolen data via a Telegram channel if victims refuse to pay. The report provides static/dynamic technical analysis (mutex resolution, CreateThread, CryptoAPI usage, NetShareEnum for lateral movement, WMI shadow copy deletion), lists targeted industries and known victims, and supplies at least one sample hash and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.