Skip to main content

Threats Tagged 'vasa locker'

View all threats tagged with 'vasa locker'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: vasa locker

Threats Tagged 'vasa locker'

Click on any threat for detailed analysis and mitigation recommendations

Toy Ghouls, a financially motivated group targeting Russian organizations since 2025, has deployed custom backdoors for the first time. Two versions were identified: mqtt-bird-agent using HiveMQ MQTT broker and matrix-bird-agent using Element messenger as command and control infrastructure. The backdoors are delivered via Windows Remote Management (WinRM) using tools like Evil-WinRM and WinRM-fs. They establish persistence as Windows services, encrypt configuration files using ChaCha20-Poly1305 algorithm, and execute commands via PowerShell or command line. The backdoors collect system metrics including CPU load, memory, and disk usage, and communicate with attackers through unconventional channels. This represents a significant evolution from their previous reliance on public GitHub tools and leaked ransomware builders to custom-developed malware.

Join the discussion

GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.

Join the discussion

GOLD SALEM is a financially motivated cybercrime group deploying Warlock ransomware through sophisticated tradecraft, including exploiting SharePoint vulnerabilities for initial access. Over six months and 11 incidents, they targeted IT, industrial, and technology sectors using ransomware variants such as Warlock, LockBit, and Babuk. Their operations involve advanced techniques like zero-day exploitation and repurposing legitimate tools (Velociraptor, VMTools AV killer, Cloudflared) to evade detection and maintain persistence. Executables are often named after victim organizations, indicating targeted attacks. While evidence suggests possible Chinese origins, the group primarily pursues financial gain. The threat poses a medium severity risk but demonstrates capabilities that could escalate impact if defenses are weak. European organizations in critical infrastructure and technology sectors should be vigilant against these tactics.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: vasa locker
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses