First
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:55:25
- Profile updated
- 2026-07-07 13:27:31
Context
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Used by threat actors
- 2015 Ukraine Electric Power Attack (campaign)
- 2023 Ivanti EPMM APT Vulnerability Exploits (campaign)
- C0033 (campaign)
- Pikabot Distribution Campaigns 2023 (campaign)
- ShadowRay (campaign)
- Velvet Ant Cisco Network Switches Exploit Activity (CVE-2024-20399) (campaign)
Reports & references
- id-ransomware.blogspot.co.il — First Ransomware (report)