Hexalocker-v2-being-proliferated-by-Skuld-Stealer
ID: 9350c510-b7ff-5313-adcf-96732066c1ba
STIX ID: report--9350c510-b7ff-5313-adcf-96732066c1ba
Feed Name: Cyble Blog
The report analyzes HexaLocker V2, a Go-compiled ransomware variant that first deploys the open-source Skuld stealer to collect browser and user data, exfiltrates victim files to hexalocker.xyz, and then encrypts files using ChaCha20 (creating .HexaLockerV2 files) after deriving keys with Argon2 and using AES-GCM for string obfuscation; it also establishes persistence via an HKCU Run entry, replaces previous comms with a unique victim hash and web chat, and includes IOCs (SHA-256 hashes and URLs), MITRE mappings, and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
