Bl00dy – New Ransomware Strain Active in the Wild
ID: 6f7e137f-1ca5-5c05-8720-88f2fb385981
STIX ID: report--6f7e137f-1ca5-5c05-8720-88f2fb385981
Feed Name: Cyble Blog
Bl00dy is a newly observed ransomware family performing double-extortion attacks: it encrypts files (appending .bl00dy), drops ransom notes, and publishes stolen data via a Telegram channel if victims refuse to pay. The report provides static/dynamic technical analysis (mutex resolution, CreateThread, CryptoAPI usage, NetShareEnum for lateral movement, WMI shadow copy deletion), lists targeted industries and known victims, and supplies at least one sample hash and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
