logo

Moisha Ransomware In Action

ID: 73b7325e-06a0-5319-b7fc-7293c2e36fb6

STIX ID: report--73b7325e-06a0-5319-b7fc-7293c2e36fb6

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

Cyble Research Labs provides a technical analysis of the Moisha .NET-based ransomware (SHA256 b3ebc3...), describing its targeted double-extortion behavior, encryption (AES/RSA), persistence and single-instance mutex, service/process termination, Defender disabling and shadow copy deletion, network spreading methods, and the ransom note with contact details; the report includes IOCs, MITRE ATT&CK mappings, and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.