Pro-Russian Hacktivists Targeting Adversaries With Killnet
ID: abbefafd-fb03-5827-af5b-4940294c4f6f
STIX ID: report--abbefafd-fb03-5827-af5b-4940294c4f6f
Feed Name: Cyble Blog
This report analyzes a destructive Killnet ransomware sample (SHA256 db1c8ddcdfea9...) attributed to the pro‑Russian Killnet hacktivist group: it documents persistence via a dropped cmd.exe in AppData and a startup shortcut, privilege escalation (runas), deletion of shadow copies/backups, targeted encryption of many file types with a ".killnet" extension, desktop lock/notice, and includes IOCs and mitigation recommendations; the actors also solicit funds and propaganda via a large Telegram channel.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
