DiscoverCYFIRMA ResearchCYFIRMA Research- LithiumWare Ransomware
CYFIRMA Research- LithiumWare Ransomware

CYFIRMA Research- LithiumWare Ransomware

Update: 2025-03-11
Share

Description

The CYFIRMA research has identified a new ransomware variant named LithiumWare, showcasing advanced capabilities designed to disrupt, encrypt, and steal. 

Key Features of LithiumWare:

  • Data Theft: Exhibits activities indicative of stealing personal data, including detecting crypto-addresses.
  • Persistence: Creates files in the startup directory, manipulates desktop.ini for cloaking, and executes services like svchost.exe.
  • Reconnaissance: Reads machine GUIDs, security settings, and environment variables to tailor attacks.
  • Misuse of Legitimate Software: Drops and executes files via trusted programs like msedge.exe and WinRAR.exe to evade detection.

Link to the Research Report: LithiumWare Ransomware - CYFIRMA

#Cybersecurity #Ransomware #LithiumWare #ThreatIntelligence  #MalwareDetection #ExternalThreatLandscapeManagement #ETLM #CYFIRMA

https://www.cyfirma.com/

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

CYFIRMA Research- LithiumWare Ransomware

CYFIRMA Research- LithiumWare Ransomware

CYFIRMA