m0yv

Malware type
virus, ransomware
Family
Malware family
Last IoC activity
2026-07-08 19:09:06
Profile updated
2026-07-07 13:45:45

Context

Modular x86/x64 file infector created/used by Maze ransomware developer. According to the author, it has been mistakenly tagged by AVs as Expiro.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_M0Yv_Auto (yara-rule)

Reports & references

  • securityaffairs.co — Egregor Sekhmet Decryption Keys (report)
  • bleepingcomputer.com — Ransomware Dev Releases Egregor Maze Master Decryption Keys (report)
  • youtu.be — 3Rybkortfnk (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.M0Yv (report)
  • github.com — Dga.Py (report)
  • github.com — Dga.Py (report)

External references