logo

A Deep-dive Analysis of VENOMOUS Ransomware

ID: 8cfb394e-d20a-57f8-86ed-791a42e44860

STIX ID: report--8cfb394e-d20a-57f8-86ed-791a42e44860

Feed Name: Cyble Blog

Threat Score
72/100

Date Published: 2024-03-14

Date Updated: 2026-07-20

...
...

Cyble Research Labs provides a technical analysis of VENOMOUS ransomware: a Python x64 console application that encrypts files using AES-256 (per-file IV), appends a .VENOMOUS/.venomnous extension, attempts to stop mssql/MySQL processes to impact databases, and drops a ransom note (SORRY-FOR-FILES.txt) that points victims to a Tor site and Telegram contact; the report includes extracted/decompiled source code, observed behaviours, IOCs (SHA256 hash, onion URL, Telegram ID), and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.