SAGE
Aliases: Saga
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-06-15 17:56:57
- Profile updated
- 2026-07-07 13:26:06
Targeted industries: financial-services healthcare-and-pharmaceutical
Context
SAGE is a ransomware family known for encrypting files and demanding a ransom for decryption. It has been observed targeting various industries and utilizing robust encryption techniques to lock victims' data.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Sage_Ransom_Auto (yara-rule)
Reports & references
- isc.sans.edu — 21959 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Sage Ransom (report)
- malware-traffic-analysis.net — Index (report)
- cert.pl — Sage 2 0 Analysis (report)
- blog.malwarebytes.com — Explained Sage Ransomware (report)
- govcert.admin.ch — Saga 2.0 Comes With Ip Generation Algorithm Ipga (report)