Blogs
Malware Library
Zero-Dwell Threat Intelligence Reports
Static Go Ransomware Deployed as enc.exe Exhibits Controlled Timer-Driven Execution
.exe
64bits
MSIL-Based Ploutus Variant Leveraging NCR APTRA XFS Framework for ATM Control
.exe
assembly
payload
Static Go Ransomware Leveraging Thread Context Rewriting and Waitable Timers
.exe
64bits
payload
Static 64-Bit Gornsm Variant Exhibits Svchost Masquerade and Controlled Thread Rewriting
.exe
64bits
Vectored Exception Handling and Memory Allocation APIs Define NightSpire Runtime Stack
.exe
64bits
payload
NightSpire Encoder Variant Accesses Windows Credential Vault Prior to Encryption Stage
.exe
64bits
High-Severity Encoder Build Leveraging Waitable Timers and Vectored Exception Handling
.exe
64bits
Static 4.7MB Go Ransomware Implant Deployed as 5uy9qxq91.exe in Windows Path
.exe
64bits
payload
NightSpire Encoder Sample Manipulates desktop.ini and Browser Credential Stores
.exe
Browser Credential File Access and Thread Context Control Observed in NightSpire Sample
.exe
64bits
payload
Encoder-Class NightSpire Implant Identified as enc.exe in Windows Deployment Path
.exe
64bits
NightSpire Encoder Build (Go 1.24.1) Identified with 57-Engine Ransomware Consensus
.exe
64bits
Posts navigation
← Previous
1
2
3
4
5
…
61
Next →