216.73.216.6

New Ymir ransomware discovered used together with RustyStealer

· Published 11/11/2024 11:13 · Modified 11/11/2024 21:55

Export JSON

Essential information

Published
11/11/2024 11:13
Modified
11/11/2024 21:55
Tags
2024-11-11 chacha20 encryption incident response powershell ransomware rustystealer systembc ymir
Related entities
9 techniques (mitre), 3 malware, 2 others

Description

A new called was discovered during an case. It uses memory operations to evade detection and employs the cipher for . The attackers gained initial access via commands and installed tools like Process Hacker before deploying . The encrypts files, appends the .6C5oy2dVr6 extension, and drops PDF ransom notes. It uses to self-delete after execution. A test variant was also identified. The attack was preceded by infections with malware and scripts used for data exfiltration. The incident highlights the connection between initial access brokers and groups.

External references