Low-profile Threat Actor Mimics NoEscape Ransomware
ID: e33371c1-2711-5b2f-82eb-bedd9f4c2544
STIX ID: report--e33371c1-2711-5b2f-82eb-bedd9f4c2544
Feed Name: Cyble Blog
Cyble Research & Intelligence Labs discovered a malicious Readme.txt.bat that connects to an SMB share to download an evolving PowerShell ransomware (combined.ps1) which exfiltrates files to an attacker SMB path, encrypts numerous file types using Rijndael with Base64-encoded keys stored on the remote SMB server, and drops a ransom note claiming to be NoEscape demanding 30 BTC; the sample appears to be in a testing phase with evident operational weaknesses (accessible keys, no leak site), and the report provides IOCs, a YARA rule, MITRE mappings, and recommended mitigations such as application whitelisting and SMB monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
