splinter_code · @splinter_code
53 followers · 6 posts · Server infosec.exchange

Excited to share my latest research about the group and the growing of custom-branded ransomware! ๐Ÿ”ฅ

A thread ๐Ÿงต

The ransomware variant used by the Vice Society group has a robust encryption scheme using and ChaCha20-Poly1305 algorithms.

We examine the connections between the Vice Society payload and other ransomware strains and variants.
Our analysis reveals that the codebase for the PolyVice variant has been used to build custom-branded payloads for other threat groups as well.

This is significant because it suggests that the Vice Society group is not developing their own ransomware payloads, but rather outsourcing its development.

One of the most rewarding parts was diving into the reversing process and trying to understand the logic of the PolyVice variant's code.

It's an interesting locker implementation.

More juicy details here ๐Ÿ‘‡

sentinelone.com/labs/custom-br

#vicesociety #ransomware #threat #polyvice #ntruencrypt

Last updated 2 years ago

splinter_code · @splinter_code
66 followers · 8 posts · Server infosec.exchange

Excited to share my latest research about the group and the growing of custom-branded ransomware! ๐Ÿ”ฅ

A thread ๐Ÿงต

The ransomware variant used by the Vice Society group has a robust encryption scheme using and ChaCha20-Poly1305 algorithms.

We examine the connections between the Vice Society payload and other ransomware strains and variants.
Our analysis reveals that the codebase for the PolyVice variant has been used to build custom-branded payloads for other threat groups as well.

This is significant because it suggests that the Vice Society group is not developing their own ransomware payloads, but rather outsourcing its development.

One of the most rewarding parts was diving into the reversing process and trying to understand the logic of the PolyVice variant's code.

It's an interesting locker implementation.

More juicy details here ๐Ÿ‘‡

sentinelone.com/labs/custom-br

#vicesociety #ransomware #threat #polyvice #ntruencrypt

Last updated 2 years ago