‘NoEscape’ Ransomware-as-a-Service (RaaS)
ID: f44326b8-c412-5115-9b28-9c8f0043425b
STIX ID: report--f44326b8-c412-5115-9b28-9c8f0043425b
Feed Name: Cyble Blog
**Executive Summary:** Cyble Research & Intelligence Labs observed a newly advertised Ransomware-as-a-Service (RaaS) named 'NoEscape' (May 2023) that claims C++ development, multi-platform support (Windows XP–11, Server 2003–2022, Linux distributions, VMware ESXi), ChaCha20 + RSA-2048 hybrid encryption, Safe Mode boot evasion, asynchronous LAN/SMB scanning for lateral movement, shared-key encryption options, Tor-hosted admin/leak infrastructure, affiliate recruitment and triple-extortion capabilities; the report details TTPs and business model but highlights limited evidence tying prior samples to this advertised program.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
