Trusted Design

CryptoApp ransomware: changes & active campaign

概要

Ransomware sure has had an uptick the past years; more and more variants appear while some have been leading the pack for the past years. This article is on a new ‘strain’, it dates to March this year from what I can tell. I haven’t seen any write-up or info about it yet (nor had any major incidents at $dayjob or heard of it from any other analysts). From what I can tell its still under development, this article will tell the story of this ransomware. Not even a day ago I blogged on a piece of ransomware named ‘CryptoApp’ which I discovered while it was still in its development & testing phase: [Analysis of a piece of ransomware in development: the story of ‘CryptoApp’]. After publication I was contacted by another analyst who was able to link the information from my blog to other samples from an actual campaign. He matched both PDB paths as wel as behaviour to these samples, this blog describes the changed made to CryptoApp as well as the active campaign.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

APT41

Score: 10.06
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1036.004 - Masquerade Task or Service
  • T1486 - Data Encrypted for Impact
  • T1003.003 - NTDS
MITREへのリンク →

Scattered Spider

Score: 13.77
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1217 - Browser Information Discovery
  • T1657 - Financial Theft
  • T1486 - Data Encrypted for Impact
  • T1003.003 - NTDS
MITREへのリンク →

TA505

Score: 6.99
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1486 - Data Encrypted for Impact
  • T1204.001 - Malicious Link
MITREへのリンク →

Volt Typhoon

Score: 8.91
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1217 - Browser Information Discovery
  • T1003.003 - NTDS
MITREへのリンク →

APT3

Score: 4.65
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1204.001 - Malicious Link
MITREへのリンク →

FIN13

Score: 10.24
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1036.004 - Masquerade Task or Service
  • T1657 - Financial Theft
  • T1003.003 - NTDS
MITREへのリンク →

Fox Kitten

Score: 7.72
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1036.004 - Masquerade Task or Service
  • T1003.003 - NTDS
MITREへのリンク →

APT38

Score: 11.52
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1486 - Data Encrypted for Impact
  • T1036.006 - Space after Filename
  • T1204.001 - Malicious Link
MITREへのリンク →

Moonstone Sleet

Score: 9.47
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1486 - Data Encrypted for Impact
  • T1587 - Develop Capabilities
MITREへのリンク →

Chimera

Score: 5.63
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1003.003 - NTDS
MITREへのリンク →

UNC3886

Score: 6.23
Matched TTPs:
  • T1681 - Search Threat Vendor Data
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

Contagious Interview

Score: 11.86
Matched TTPs:
  • T1681 - Search Threat Vendor Data
  • T1657 - Financial Theft
  • T1587 - Develop Capabilities
  • T1204.001 - Malicious Link
MITREへのリンク →

Kimsuky

Score: 9.82
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1657 - Financial Theft
  • T1587 - Develop Capabilities
  • T1204.001 - Malicious Link
MITREへのリンク →

FIN7

Score: 5.80
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1486 - Data Encrypted for Impact
  • T1204.001 - Malicious Link
MITREへのリンク →

APT32

Score: 3.46
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1204.001 - Malicious Link
MITREへのリンク →

Winter Vivern

Score: 3.46
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1204.001 - Malicious Link
MITREへのリンク →

Wizard Spider

Score: 5.80
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1003.003 - NTDS
  • T1204.001 - Malicious Link
MITREへのリンク →

FIN6

Score: 7.18
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1573.002 - Asymmetric Cryptography
  • T1003.003 - NTDS
MITREへのリンク →

ZIRCONIUM

Score: 3.46
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1204.001 - Malicious Link
MITREへのリンク →

Magic Hound

Score: 5.80
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1486 - Data Encrypted for Impact
  • T1204.001 - Malicious Link
MITREへのリンク →

Lazarus Group

Score: 6.23
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Storm-0501

Score: 6.96
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1657 - Financial Theft
  • T1486 - Data Encrypted for Impact
MITREへのリンク →

INC Ransom

Score: 4.86
Matched TTPs:
  • T1657 - Financial Theft
  • T1486 - Data Encrypted for Impact
MITREへのリンク →

Akira

Score: 4.86
Matched TTPs:
  • T1657 - Financial Theft
  • T1486 - Data Encrypted for Impact
MITREへのリンク →

Medusa Group

Score: 9.95
Matched TTPs:
  • T1657 - Financial Theft
  • T1486 - Data Encrypted for Impact
  • T1573.002 - Asymmetric Cryptography
  • T1003.003 - NTDS
MITREへのリンク →

Water Galura

Score: 4.86
Matched TTPs:
  • T1657 - Financial Theft
  • T1486 - Data Encrypted for Impact
MITREへのリンク →

Mustang Panda

Score: 12.37
Matched TTPs:
  • T1678 - Delay Execution
  • T1027.007 - Dynamic API Resolution
  • T1003.003 - NTDS
  • T1204.001 - Malicious Link
MITREへのリンク →

Gamaredon Group

Score: 5.90
Matched TTPs:
  • T1001 - Data Obfuscation
  • T1204.001 - Malicious Link
MITREへのリンク →

Sandworm Team

Score: 6.04
Matched TTPs:
  • T1486 - Data Encrypted for Impact
  • T1003.003 - NTDS
  • T1204.001 - Malicious Link
MITREへのリンク →

FIN8

Score: 6.45
Matched TTPs:
  • T1486 - Data Encrypted for Impact
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

TA2541

Score: 4.11
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

RedCurl

Score: 4.11
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

OilRig

Score: 4.11
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

Cobalt Group

Score: 4.11
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

APT28

Score: 8.24
Matched TTPs:
  • T1137.002 - Office Test
  • T1003.003 - NTDS
  • T1204.001 - Malicious Link
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Scattered Spider

Score: 0.81
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1217 - Browser Information Discovery
  • T1003.003 - NTDS
  • T1486 - Data Encrypted for Impact
  • T1657 - Financial Theft
MITREへのリンク →

Contagious Interview

Score: 0.74
Matched TTPs:
  • T1657 - Financial Theft
  • T1204.001 - Malicious Link
  • T1587 - Develop Capabilities
  • T1681 - Search Threat Vendor Data
MITREへのリンク →

Mustang Panda

Score: 0.74
Matched TTPs:
  • T1204.001 - Malicious Link
  • T1003.003 - NTDS
  • T1027.007 - Dynamic API Resolution
  • T1678 - Delay Execution
MITREへのリンク →

APT38

Score: 0.71
Matched TTPs:
  • T1486 - Data Encrypted for Impact
  • T1036.006 - Space after Filename
  • T1204.001 - Malicious Link
  • T1217 - Browser Information Discovery
MITREへのリンク →

Medusa Group

Score: 0.68
Matched TTPs:
  • T1486 - Data Encrypted for Impact
  • T1003.003 - NTDS
  • T1657 - Financial Theft
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

FIN13

Score: 0.65
Matched TTPs:
  • T1657 - Financial Theft
  • T1003.003 - NTDS
  • T1069 - Permission Groups Discovery
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

APT41

Score: 0.63
Matched TTPs:
  • T1486 - Data Encrypted for Impact
  • T1003.003 - NTDS
  • T1069 - Permission Groups Discovery
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

Moonstone Sleet

Score: 0.62
Matched TTPs:
  • T1486 - Data Encrypted for Impact
  • T1587 - Develop Capabilities
  • T1217 - Browser Information Discovery
MITREへのリンク →

Kimsuky

Score: 0.61
Matched TTPs:
  • T1587 - Develop Capabilities
  • T1204.001 - Malicious Link
  • T1657 - Financial Theft
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

APT28

Score: 0.56
Matched TTPs:
  • T1204.001 - Malicious Link
  • T1003.003 - NTDS
  • T1137.002 - Office Test
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る