惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

大猫的无限游戏
大猫的无限游戏
aimingoo的专栏
aimingoo的专栏
I
InfoQ
B
Blog RSS Feed
D
DataBreaches.Net
S
SegmentFault 最新的问题
P
Proofpoint News Feed
A
About on SuperTechFans
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美
小众软件
小众软件
博客园 - Franky
有赞技术团队
有赞技术团队
D
Docker
T
Tailwind CSS Blog
雷峰网
雷峰网
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Blog — PlanetScale
Blog — PlanetScale
酷 壳 – CoolShell
酷 壳 – CoolShell
B
Blog
V
Visual Studio Blog
宝玉的分享
宝玉的分享
爱范儿
爱范儿

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Rapture Ransomware: A Deep Dive into the Silent Cyber Storm
Intel 471 · 2023-05-11 · via Intel 471 Blog

Overview of the Rapture Ransomware

Rapture Ransomware is a newly-emerging threat, distinguishing itself by its lean but effective approach. Operating within a notably short lifecycle of 3-5 days, its objective is to leave as minimal a footprint as possible, thus making its actions harder to trace and analyze. An added layer of complexity comes from its use of Themida, a commercial software packer frequently employed to shield software from reverse engineering. This adds further impediments to analysis due to the packer's anti-debugging, entry point protection, and dynamic encryption features. The sectors currently known to be in Rapture's crosshairs include healthcare, education, and manufacturing.

Current Campaign Details

Rapture was first identified in early 2023, and it bears some resemblances to another variant known as "Paradise", particularly in its use of an RSA key configuration file and its compilation as a .NET executable. However, the unidentified threat actors behind Rapture and its unique behavioral patterns set it apart. Rapture's targets are typically identified through a combination of system vulnerability scans, spear-phishing emails, and the exploitation of weak systems and software.

Technical Details of the Attack from Rapture Ransomware

Rapture Ransomware's tactics place emphasis on stealth and creating difficulties for analysis. It is commonly delivered through phishing emails or by exploiting system and software vulnerabilities. Once inside the system, Rapture introduces a file with the extension ".log" and performs an initial reconnaissance that includes an inspection of firewall policies, system tool versioning, and any potentially exploitable Log4J vulnerabilities.

In its quest for elevated privileges, Rapture launches explorer.exe using the "/NOUACCHECK" command, allowing it to inherit the parent process's elevated status. This process is then used to execute the second-stage Cobalt Strike beacon downloader, which connects to a specific address to download the main beacon. This main beacon is concealed within a JavaScript file, which is then decrypted and executed. The same second-stage beacon is also used to obtain backdoor commands and potentially other payloads.

During the encryption phase, Rapture leaves notes in every directory it encrypts, often using hard-coded character strings as extensions. As we learn more about this variant and its evolving campaign, we will continue to provide updates in our Threat Hunt Packages.

GET THE FREE HUNT PACKAGES!

CHECK OUT OTHER EMERGING THREATS >