Onyx Ransomware Renames its Leak Site To “VSOP”
ID: 8babd656-17fa-5973-a5c2-1c3fca4cea12
STIX ID: report--8babd656-17fa-5973-a5c2-1c3fca4cea12
Feed Name: Cyble Blog
Onyx is a .NET-based double-extortion ransomware observed since April 2022 that exfiltrates victim data, encrypts files with the ".ampkcz" extension, and overwrites files larger than 2MB, permanently destroying them; the group has posted at least 13 victims across six countries and recently renamed its leak site to “VSOP.” The report details encryption algorithms (AES/RSA), targeted directories and file extensions, destructive behavior (file overwrite and shadow copy deletion), persistence (registry RunOnce and shortcuts), spread via mounted drives, a sample SHA256, IOCs, and recommended mitigations (backups, AV, MFA, vulnerability management).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
