logo

Hexalocker-v2-being-proliferated-by-Skuld-Stealer

ID: 9350c510-b7ff-5313-adcf-96732066c1ba

STIX ID: report--9350c510-b7ff-5313-adcf-96732066c1ba

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-10-17

Date Updated: 2026-07-16

...
...

The report analyzes HexaLocker V2, a Go-compiled ransomware variant that first deploys the open-source Skuld stealer to collect browser and user data, exfiltrates victim files to hexalocker.xyz, and then encrypts files using ChaCha20 (creating .HexaLockerV2 files) after deriving keys with Argon2 and using AES-GCM for string obfuscation; it also establishes persistence via an HKCU Run entry, replaces previous comms with a unique victim hash and web chat, and includes IOCs (SHA-256 hashes and URLs), MITRE mappings, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.