Uncovering The Dark Side of DarkBit Ransomware
ID: a8fa8cf1-da1c-5a41-b8b4-fe6de98a7f01
STIX ID: report--a8fa8cf1-da1c-5a41-b8b4-fe6de98a7f01
Feed Name: Cyble Blog
This report analyzes a politically-motivated DarkBit ransomware attack against a major Israeli university, detailing a Go-compiled binary (SHA256: 9107be160f7b639d68fe3670de58ed254d81de6aec9a41ad58d91aa814a247ff), its runtime behavior (Global mutex, drive enumeration, shadow-copy deletion via vssadmin, multithreaded encryption, file exclusions and segmentation), ransom infrastructure (TOX, Tor site) and extortion tactics (threat to sell data, 30% penalty). It includes MITRE technique mappings, a single SHA256 IOC, and recommended defensive measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
