logo

Low-profile Threat Actor Mimics NoEscape Ransomware

ID: e33371c1-2711-5b2f-82eb-bedd9f4c2544

STIX ID: report--e33371c1-2711-5b2f-82eb-bedd9f4c2544

Feed Name: Cyble Blog

Threat Score
62/100

Date Published: 2024-10-28

Date Updated: 2026-07-17

...
...

Cyble Research & Intelligence Labs discovered a malicious Readme.txt.bat that connects to an SMB share to download an evolving PowerShell ransomware (combined.ps1) which exfiltrates files to an attacker SMB path, encrypts numerous file types using Rijndael with Base64-encoded keys stored on the remote SMB server, and drops a ransom note claiming to be NoEscape demanding 30 BTC; the sample appears to be in a testing phase with evident operational weaknesses (accessible keys, no leak site), and the report provides IOCs, a YARA rule, MITRE mappings, and recommended mitigations such as application whitelisting and SMB monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.