TF-MAL-elf.ransomexx2
📛 Threat Title
Malware family: RansomExx2
Description
ThreatFox malware family `elf.ransomexx2`. Printable name: RansomExx2.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:malpedia.caad.fkie.fraunhofer.de
According to IBM Security X-Force, this is a new but functionally very similar version of RansomExx, fully rewritten in Rust and internally referred to as RansomExx2 .
-
web:qadit.com
Several ransomware developers have released Rust versions of their malware including BlackCat, Hive, and Zeon, with RansomExx2 being the most recent addition. X-Force has also analysed an ITG23 crypter written in Rust, along with the CargoBay family of backdoors and downloaders.
-
web:securityaffairs.com
The operators of the RansomExx ransomware (aka Defray777 and Ransom X) have developed a new variant of their malware , tracked as RansomExx2 , that was ported into the Rust programming language. The move follows the decision of other ransomware gangs, like Hive, Blackcat, and Luna, of rewriting their ransomware into Rust programming language.
-
web:virtualbits.com
The operators of the RansomExx ransomware (aka Defray777 and Ransom X) have developed a new variant of their malware , tracked as RansomExx2 , that was ported into the Rust programming language. The move follows the decision of other ransomware gangs, like Hive, Blackcat, and Luna, of rewriting their ransomware into Rust programming language.
-
web:www.broadcom.com
The reason for the switch to Rust is mainly due to higher AV evasion rates across various vendors on malware written in this programming language. The new variant RansomExx2 targets Linux environments for data encryption and will append random extensions to the encrypted files.
-
web:www.ibm.com
Several ransomware developers have released Rust versions of their malware including BlackCat, Hive, and Zeon, with RansomExx2 being the most recent addition. X-Force has also analysed an ITG23 crypter written in Rust, along with the CargoBay family of backdoors and downloaders.
-
web:www.secureblink.com
The developers behind RansomExx also created the PyXie malware , Vatet loader, and Defray ransomware strains, IBM explained. The new variant, which goes by the moniker RansomExx2 , is built to run on the Linux operating system, but IBM noted that the group typically creates versions for Windows as well.
-
web:www.sentinelone.com
What is RansomEXX Ransomware? RansomEXX (aka Defray, Defray777), a multi-pronged extortion threat, has been observed in the wild since late 2020. RansomEXX is associated with attacks against the Texas Department of Transportation, Groupe Atlantic, and several other large enterprises. There are Windows and Linux variants of this malware family , and they are known for their limited and exclusive ...
-
web:www.thodex.com
Anti- malware software must utilize advanced detection techniques, such as heuristics and machine learning algorithms, to effectively block RansomEXX. Additionally, monitoring network traffic for unusual patterns or communication with known command-and-control servers can reveal indicators of compromise. Mitigation and Remediation Techniques
-
web:www.watchguard.com
RansomExx2 is the next iteration of the Defray family of ransomware. As assumed, RansomExx2 is a direct variant of RansomExx and contains similar functionality. This variant is programmed in the Rust programming language and was discovered in mid-November. The first known victim was discovered in 2022.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.