RURansom Malware: New Wiper Attack On Russia
ID: a6357ac5-3954-59d0-931d-ee70189f1f21
STIX ID: report--a6357ac5-3954-59d0-931d-ee70189f1f21
Feed Name: Cyble Blog
Cyble Research Labs provides a deep-dive analysis of RURansom, a destructive .NET-based wiper discovered attacking Russia: the sample checks geolocation via hardcoded ipify API, attempts privilege escalation (including a PowerShell elevation technique), scans local/removable/network drives, encrypts files using AES-CBC while deleting .bak backups, propagates by copying itself (renamed as a Russia-Ukraine_War-Update.doc.exe) across connected systems, and drops Russian-language ransom notes; the report includes code excerpts, MITRE ATT&CK mappings, and multiple IoCs (hashes) for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
