惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
N
Netflix TechBlog - Medium
F
Fortinet All Blogs
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
宝玉的分享
宝玉的分享
Y
Y Combinator Blog
博客园 - 聂微东
WordPress大学
WordPress大学
酷 壳 – CoolShell
酷 壳 – CoolShell
B
Blog RSS Feed
小众软件
小众软件
The GitHub Blog
The GitHub Blog
S
SegmentFault 最新的问题
Hugging Face - Blog
Hugging Face - Blog
Jina AI
Jina AI
Microsoft Azure Blog
Microsoft Azure Blog
V
V2EX
B
Blog
H
Help Net Security
D
Docker
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
罗磊的独立博客
月光博客
月光博客
博客园 - 司徒正美

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Rapture Ransomware: A Deep Dive into the Silent Cyber Storm
Intel 471 · 2023-05-11 · via Intel 471 Blog

Overview of the Rapture Ransomware

Rapture Ransomware is a newly-emerging threat, distinguishing itself by its lean but effective approach. Operating within a notably short lifecycle of 3-5 days, its objective is to leave as minimal a footprint as possible, thus making its actions harder to trace and analyze. An added layer of complexity comes from its use of Themida, a commercial software packer frequently employed to shield software from reverse engineering. This adds further impediments to analysis due to the packer's anti-debugging, entry point protection, and dynamic encryption features. The sectors currently known to be in Rapture's crosshairs include healthcare, education, and manufacturing.

Current Campaign Details

Rapture was first identified in early 2023, and it bears some resemblances to another variant known as "Paradise", particularly in its use of an RSA key configuration file and its compilation as a .NET executable. However, the unidentified threat actors behind Rapture and its unique behavioral patterns set it apart. Rapture's targets are typically identified through a combination of system vulnerability scans, spear-phishing emails, and the exploitation of weak systems and software.

Technical Details of the Attack from Rapture Ransomware

Rapture Ransomware's tactics place emphasis on stealth and creating difficulties for analysis. It is commonly delivered through phishing emails or by exploiting system and software vulnerabilities. Once inside the system, Rapture introduces a file with the extension ".log" and performs an initial reconnaissance that includes an inspection of firewall policies, system tool versioning, and any potentially exploitable Log4J vulnerabilities.

In its quest for elevated privileges, Rapture launches explorer.exe using the "/NOUACCHECK" command, allowing it to inherit the parent process's elevated status. This process is then used to execute the second-stage Cobalt Strike beacon downloader, which connects to a specific address to download the main beacon. This main beacon is concealed within a JavaScript file, which is then decrypted and executed. The same second-stage beacon is also used to obtain backdoor commands and potentially other payloads.

During the encryption phase, Rapture leaves notes in every directory it encrypts, often using hard-coded character strings as extensions. As we learn more about this variant and its evolving campaign, we will continue to provide updates in our Threat Hunt Packages.

GET THE FREE HUNT PACKAGES!

CHECK OUT OTHER EMERGING THREATS >