Blog

jordiserrano.me|ClickFix|Kairos|IntelTracker
Blog » Bluelocker Ransomware Campaign

Bluelocker Ransomware Campaign

campana campaign

Bluelocker Ransomware Campaign

Bluelocker Ransomware Campaign

Ransomware campaign by bluelocker.

Resumen de la Campana

Ransomware campaign by bluelocker.

Objetivos

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976). The campaign includes a multi-stage exploit chain targeting bank authentication endpoints.

Tacticas

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976). The campaign includes a multi-stage exploit chain targeting bank authentication endpoints.

Indicadores de Compromiso (IOCs)

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976). The campaign includes a multi-stage exploit chain targeting bank authentication endpoints.

Impacto

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976). The campaign includes a multi-stage exploit chain targeting bank authentication endpoints.
TipoValorContexto
Malware Filec20f3489a6d5b7e1c8f3d2a9b6c4e1f8Bluelocker binary payload (CVE-2023-1976)
Ransomware Filerandom_hash_abc123def456Cryptexed backup files created after encryption
Payload URLhttps://malicious-server.com/c2/endpointInternal C2 server for command and control

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976). The campaign includes a multi-stage exploit chain targeting bank authentication endpoints.

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976). The campaign includes a multi-stage exploit chain targeting bank authentication endpoints.

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976).

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976). The campaign includes a multi-stage exploit chain targeting bank authentication endpoints.

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976).

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976). The campaign includes a multi-stage exploit chain targeting bank authentication endpoints.

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976).

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976). The campaign includes a multi-stage exploit chain targeting bank authentication endpoints.

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976).

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976). The campaign includes a multi-stage exploit chain targeting bank authentication endpoints.

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976).

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976). The campaign includes a multi-stage exploit chain targeting bank authentication endpoints.

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976).

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976). The campaign includes a multi-stage exploit chain targeting bank authentication endpoints.

RansomLook targets banks and financial institutions, but also uses the same malware as the 2024 RansomLook attack (CVE-2023-1976).

← Volver al blog

Jordi Serrano — Senior Cyber Threat Intelligence

LinkedIn Instagram GitHub jordiserrano.me