core
- First seen
- 2025-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:56:13
Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing retail-and-hospitality
Context
Core ransomware surfaced in early 2025 as a new variant within the broader Makop family. It employs a single-extortion model, focusing on encrypting files and demanding payment, without public data-leak threats. The malware appends the .core extension to encrypted files and is delivered via typical exploit vectors known to RaaS campaigns. Core does not showcase advanced double-extortion tactics seen in other modern strains, but it stands out for its familial lineage and continued evolution from Makop ancestors.
Reports & references
- ransomlook.io — Core (report)
- Broadcom/Symantec — Core Ransomware A New Makop Variant (report)