core

First seen
2025-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:56:13

Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing retail-and-hospitality

Context

Core ransomware surfaced in early 2025 as a new variant within the broader Makop family. It employs a single-extortion model, focusing on encrypting files and demanding payment, without public data-leak threats. The malware appends the .core extension to encrypted files and is delivered via typical exploit vectors known to RaaS campaigns. Core does not showcase advanced double-extortion tactics seen in other modern strains, but it stands out for its familial lineage and continued evolution from Makop ancestors.

Reports & references

  • ransomlook.io — Core (report)
  • Broadcom/Symantec — Core Ransomware A New Makop Variant (report)

External references