Explorer

First seen
2022-05-12 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 16:16:03

Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality

Context

Explorer is a ransomware that encrypts files on infected systems, demanding a ransom for decryption keys. It targets various industries and is known for its sophisticated encryption techniques.

Detection coverage

  • 4 YARA rules

Detection rules

  • DITEKSHEN_INDICATOR_TOOL_Backstab (yara-rule)
  • DITEKSHEN_INDICATOR_RTF_LNK_Shell_Explorer_Execution (yara-rule)
  • SEKOIA_Apt_Unc4990_Explorer_Ps1 (yara-rule)
  • SEKOIA_Apt_Unc4990_Explorer_Ps1_Reverse_B64 (yara-rule)