Kanti: A NIM-Based Ransomware Unleashed in the Wild
ID: d1f60a5e-20d5-5d33-9db0-529ed4ba6845
STIX ID: report--d1f60a5e-20d5-5d33-9db0-529ed4ba6845
Feed Name: Cyble Blog
Threat Score
Cyble Research and Intelligence Labs analyzed a NIM-built ransomware strain named “Kanti” distributed via a malicious ZIP/LNK lure targeting cryptocurrency users; the Windows PE executes despite a .zip extension, enumerates files (excluding system items), encrypts data using secure RNG (BCryptGenRandom), renames files with the .kanti extension, drops a Kanti.html ransom note, and includes file hashes and IOCs along with mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
