logo

RURansom Malware: New Wiper Attack On Russia

ID: a6357ac5-3954-59d0-931d-ee70189f1f21

STIX ID: report--a6357ac5-3954-59d0-931d-ee70189f1f21

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-18

Date Updated: 2026-07-16

...
...

Cyble Research Labs provides a deep-dive analysis of RURansom, a destructive .NET-based wiper discovered attacking Russia: the sample checks geolocation via hardcoded ipify API, attempts privilege escalation (including a PowerShell elevation technique), scans local/removable/network drives, encrypts files using AES-CBC while deleting .bak backups, propagates by copying itself (renamed as a Russia-Ukraine_War-Update.doc.exe) across connected systems, and drops Russian-language ransom notes; the report includes code excerpts, MITRE ATT&CK mappings, and multiple IoCs (hashes) for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.