Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Our experts managed to intercept a pre-release sample of a new Ransomware-as-a-Service (RaaS) variant called “CashRansomware” which is currently in active development.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The data flow and control flow of the sample are obfuscated using Eziriz .NET Reactor.
It also detects the presence of sandboxie and any.run sandbox... The malware has anti VM features and can detect if the “Manifacturer” contains “microsoft corporation” or “vmware”
CashRansomware is programmed to avoid infecting systems located in Russia and other Commonwealth of Independent States (CIS) countries. This selective targeting is achieved through geolocation checks and system language settings
Every device connected to the compromised computer is systematically explored by enumerating drive letters. This process allows the malware to identify and target additional storage devices, such as external hard drives, USB drives, and network shares
It also detects the presence of sandboxie and any.run sandbox... The malware has anti VM features and can detect if the “Manifacturer” contains “microsoft corporation” or “vmware”
CashRansomware is programmed to avoid infecting systems located in Russia and other Commonwealth of Independent States (CIS) countries. This selective targeting is achieved through geolocation checks and system language settings
It autonomously encrypts files on the infected system and subsequently displays a pop-up window demanding cryptocurrency payment for decryption.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.