CYFIRMA Research- LithiumWare Ransomware
Manage episode 470775510 series 3472819
The CYFIRMA research has identified a new ransomware variant named LithiumWare, showcasing advanced capabilities designed to disrupt, encrypt, and steal.
Key Features of LithiumWare:
- Data Theft: Exhibits activities indicative of stealing personal data, including detecting crypto-addresses.
- Persistence: Creates files in the startup directory, manipulates desktop.ini for cloaking, and executes services like svchost.exe.
- Reconnaissance: Reads machine GUIDs, security settings, and environment variables to tailor attacks.
- Misuse of Legitimate Software: Drops and executes files via trusted programs like msedge.exe and WinRAR.exe to evade detection.
Link to the Research Report: LithiumWare Ransomware - CYFIRMA
#Cybersecurity #Ransomware #LithiumWare #ThreatIntelligence #MalwareDetection #ExternalThreatLandscapeManagement #ETLM #CYFIRMA
https://www.cyfirma.com/
200 episodes