216.73.216.6

Kryptina RaaS - From Unsellable Cast-Off to Enterprise Ransomware

· Published 24/09/2024 14:42 · Modified 24/09/2024 15:08

Export JSON

Essential information

Published
24/09/2024 14:42
Modified
24/09/2024 15:08
Tags
2024-09-24 CVE-2024-21338 kryptina mallox
Related entities
1 vulnerabilities (cve), 21 observables, 1 intrusion sets (apt), 10 techniques (mitre), 2 malware

Description

This analysis examines the evolution of , a ransomware-as-a-service platform, from a free tool on public forums to being actively used in enterprise attacks under the ransomware family. In May 2024, a affiliate leaked staging server data, revealing their Linux ransomware was based on a modified version of . The affiliate made superficial changes to source code and documentation, removing branding but retaining core functionality. This adoption exemplifies the commoditization of ransomware tools, complicating malware tracking as affiliates blend different codebases into new variants. The report details the similarities and differences between the original RaaS and the modified version, including encryption methods, ransom note templates, and configuration files.

External references