Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Unpacking Peter Thiel’s big bet on solar-powered cow collars

    April 4, 2026

    Embattled startup Delve has ‘parted ways’ with Y Combinator

    April 4, 2026

    Anthropic says Claude Code subscribers will need to pay extra for OpenClaw usage

    April 4, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Unpacking Peter Thiel’s big bet on solar-powered cow collars
    • Embattled startup Delve has ‘parted ways’ with Y Combinator
    • Anthropic says Claude Code subscribers will need to pay extra for OpenClaw usage
    • Anthropic buys biotech startup Coefficient Bio in $400M deal: Reports
    • The Facebook insider building content moderation for the AI era
    • Commonwealth Fusion Systems leans on magnets for near-term revenue
    • Diverse teams start with diverse VCs
    • The reputation of troubled YC startup Delve has gotten even worse
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Security»Open-source DFIR Velociraptor was abused in expanding ransomware efforts
    Security

    Open-source DFIR Velociraptor was abused in expanding ransomware efforts

    TechurzBy TechurzOctober 10, 2025No Comments1 Min Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Ransomware
    Share
    Facebook Twitter LinkedIn Pinterest Email


    “Velociraptor played a significant role in this campaign, ensuring the actors maintained stealthy persistent access while deploying LockBit and Babuk ransomware,” Talos researchers added. “The addition of this tool in the ransomware playbook is in line with findings from Talos’ ‘2024 Year in Review,’ which highlights that threat actors are utilizing an increasing variety of commercial and open-source products.”

    Attribution and the ransomware cocktail

    Talos links the campaign to Storm-2603, a suspected China-based threat actor, citing matching TTPs like the use of ‘cmd.exe’, disabling Defender protections, creating scheduled tasks, and manipulating Group Policy Objects. The use of multiple ransomware strains in a single operation – Warlock, LockBit, and Babuk – also bolstered confidence in this attribution.

    “Talos observed ransomware executables on Windows machines that were identified by EDR solutions as LockBit, and encrypted files with the Warlock extension ‘xlockxlock’,” the researchers added. “There was also a Linux binary on ESXi servers flagged as the Babuk encryptor, which achieved only partial encryption and appended files with ‘.babyk’.”

    abused DFIR Efforts expanding opensource Ransomware Velociraptor
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleNorth Korean Scammers Are Doing Architectural Design Now
    Next Article Stealit Malware Abuses Node.js Single Executable Feature via Game and VPN Installers
    Techurz
    • Website

    Related Posts

    Opinion

    Mercor says it was hit by cyberattack tied to compromise of open-source LiteLLM project

    April 1, 2026
    Opinion

    Palmer Luckey says the coolest thing about Anduril expanding to Long Beach is the fighter jets

    January 23, 2026
    Opinion

    Canadian peer-to-peer clothing rental company Rax is expanding to the U.S.

    December 16, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Our Picks

    Unpacking Peter Thiel’s big bet on solar-powered cow collars

    April 4, 2026

    Embattled startup Delve has ‘parted ways’ with Y Combinator

    April 4, 2026

    Anthropic says Claude Code subscribers will need to pay extra for OpenClaw usage

    April 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.