logo

NoEscape Ransomware Uses Reflective DLL Injection Tactics

ID: ed71d300-204b-5b07-ba7f-c60066148910

STIX ID: report--ed71d300-204b-5b07-ba7f-c60066148910

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-28

Date Updated: 2026-07-17

...
...

This report analyzes NoEscape, a newly observed Ransomware-as-a-Service actively advertised to affiliates that can produce Windows (EXE/DLL/reflective DLL) and Linux/ESXi (ELF) payloads; it documents technical behaviors (mutex, UAC bypass via EnableLUA/ConsentPromptBehaviorAdmin, process/service termination, CryptoAPI and ChaCha20 encryption, backup/shadowcopy deletion), ESXi-targeting scripts that stop VMs and encrypt VM/NFS volumes, dropped ransom notes, IOCs (file hashes and script names), ATT&CK mappings, and recommended defensive measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.