X/Twitter (@TrendMicroRSRCH) Mar 2025
Thread
SmokeLoader Delivers W3CryptoLocker via Steganography
RansomwareDefense EvasionSteganography
Thread analyzing SmokeLoader's use of steganography techniques to deliver W3CryptoLocker ransomware payloads while evading detection mechanisms.
Related Research
Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques
Discovered Agenda ransomware deploying Linux variants on Windows systems via remote management tools and BYOVD techniques for cross-platform evasion.
RansomwareCross-Platform
Agenda Ransomware Group Adds SmokeLoader and NETXLOADER to Their Arsenal
Uncovered Agenda ransomware group adopting SmokeLoader and a new loader named NETXLOADER for improved delivery and evasion.
RansomwareDefense Evasion
Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
Documented Cerber ransomware operators rapidly weaponizing CVE-2023-22518 in Atlassian Confluence for initial access and encryption deployment.
RansomwareDefense Evasion
Crypto24 Ransomware Group Blends Legitimate Tools with Custom Malware for Stealth Attacks
Analyzed Crypto24 ransomware group's technique of blending legitimate tools with custom malware to bypass EDR and security technologies.
RansomwareDefense Evasion