LABScon24 Replay | Kryptina RaaS: From Unsellable Cast-off to Enterprise Ransomware
Kryptina RaaS 是一个专注于 Linux 的勒索软件即服务(RaaS)平台,最初作为无法出售的赠品出现。近期 Mallox 勒索软件关联演员暂存服务器泄露事件揭示了 Kryptina 如何被改编用于企业攻击。演讲中 Jim Walter 分析了该平台近期发展、威胁 actors 的吸引力以及针对受害者的潜在影响,并详细解读了 2024 年 5 月 Mallox 泄露内容及 Kryptina 平台改进情况。 2025-3-26 13:0:16 Author: www.sentinelone.com(查看原文) 阅读量:8 收藏

Kryptina RaaS is a Linux-focused RaaS platform & service that started life as an unsellable giveaway. However, large-scale ransomware operations are now adopting the platform to extend their reach into Linux and cloud environments.

In this talk, Jim Walter reveals how a recent leak from a Mallox ransomware-affiliated actor’s staging server provided insight into how Kryptina has been adapted for use in enterprise attacks.

The presentation focuses on recent developments and provides an understanding of why threat actors are attracted to the Kryptina platform, and what this means in the context of victims and targeting.

Jim also dissects what was included in the May 2024 Mallox leak and improvements and modifications that threat actors have made to the Kryptina platform.

About the Author

Jim Walter is a Senior Threat Researcher at SentinelOne focusing on evolving trends, actors, and tactics within the thriving ecosystem of cybercrime and crimeware. He specializes in the discovery and analysis of emerging cybercrime “services” and evolving communication channels leveraged by mid-level criminal organizations.

About LABScon

This presentation was featured live at LABScon 2024, an immersive 3-day conference bringing together the world’s top cybersecurity minds, hosted by SentinelOne’s research arm, SentinelLABS.

Keep up with all the latest on LABScon 2025 here.


文章来源: https://www.sentinelone.com/labs/labscon24-replay-kryptina-raas-from-unsellable-cast-off-to-enterprise-ransomware/
如有侵权请联系:admin#unsafe.sh