Lime

Malware type
ransomware
Last IoC activity
2026-07-22 01:55:25
Profile updated
2026-07-07 16:03:48

Targeted industries: education-and-nonprofits financial-services government-and-public-sector healthcare-and-pharmaceutical retail-and-hospitality

Context

Lime is a type of ransomware that encrypts victim files and demands a ransom for decryption. It has been observed targeting multiple industries, focusing on extracting financial gain from the compromised entities.

Detection coverage

  • 4 YARA rules

Detection rules

  • SIGNATURE_BASE_HKTL_NET_GUID_Lime_Downloader (yara-rule)
  • SIGNATURE_BASE_HKTL_NET_GUID_Lime_Crypter (yara-rule)
  • SIGNATURE_BASE_HKTL_NET_GUID_Lime_Miner (yara-rule)
  • SIGNATURE_BASE_HKTL_NET_GUID_Lime_RAT (yara-rule)