Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Moonrise

158
Global rank
148 infographic chevron month
Month rank
191 infographic chevron week
Week rank
0
IOCs

Moonrise RAT is a newly discovered Go-based remote access trojan with zero detections at launch, featuring credential theft, keylogging, webcam access, clipboard hijacking, and UAC bypass.

RAT
Type
Unknown
Origin
1 February, 2026
First seen
12 August, 2026
Last seen

How to analyze Moonrise with ANY.RUN

RAT
Type
Unknown
Origin
1 February, 2026
First seen
12 August, 2026
Last seen

IOCs

IP addresses
40.126.31.67
74.125.250.129
150.171.28.11
74.178.240.61
48.209.138.189
57.153.246.3
150.171.109.194
64.89.161.119
2.23.246.9
23.11.40.157
172.211.123.248
2.16.204.141
150.171.22.17
150.171.109.193
23.59.18.102
23.48.23.143
48.209.138.168
150.171.27.11
149.102.229.136
142.251.14.100
Hashes
3eb38ae99653a7dbc724132ee240f6e5c4af4bfe7c01d31d23faf373f9f2eaca
226eec4486509917aa336afebd6ff65777b75b65f1fb06891d2a857a9421a974
32d83ff113fef532a9f97e0d2831f8656628ab1c99e9060f0332b1532839afd9
9b1fbf0c11c520ae714af8aa9af12cfd48503eedecd7398d8992ee94d1b4dc37
44071e0fcffb9a9a32e8fa7010bb18dbc41afd0b176f81bf700b15b638a88a51
696e930706b5d391eb8778f73b0627ffc2be7f6c9a3e7659170d9d37fc4a97b5
49aff5690cb9b0f54f831351aa0f64416ba180a0c4891a859fa7294e81e9c8e3
bf2fa4c57095e0be63e8cd1ae6d2389d6417a91d8c9e1970eeee5363c46f0d27
0c75acb008dd5c918d8a1a73c22fa7c503961481bf1708f6bda0da58693c3c08
f4da114b473c34e0946b12289f6e802fcede2f66013d4f184c729a1f8ae7350e
24c09721c3cb4f3fe7eb403113375257197bed808295c6b85532409b6664db45
5635587f6ffb152c027b4357092fe78168e31cbc7f6be694c627f819c1ad1d73
20be1732675fedf380010b09936ed65c71bb761d0a05732215ef0795b5aba606
1847f8517d8f26c856adbf08df3996d5f3b7ab61378199c138346bfe29675f01
7b06f3b7040901e7dbd2884ba534d43e73013ce0677bc725d53bccd54759ad5e
957b57bac9d8a927be5cfbb74d23dcf69cf2678ecd4fcf2158a391f7a02fea87
ac1431e61f8c6c56ef96860dc8a8ddf840dbf6965af6b920d811b7e39adab6b1
ef7ffd8792b482829f31924241e6bd12dccdfdf404a0781bb28747c308649c0a
ecc84d9a40448772697c14f27b1297fcdce12df30d008a7d4149a6aa587d85a8
f1e01eeb90c0842f7af927f65d034fc93fdbcbcb9b9ea7e31c79761c316c8fb8
Domains
www.bing.com
settings-win.data.microsoft.com
config.edge.skype.com
ocsp.digicert.com
api.edgeoffer.microsoft.com
slscr.update.microsoft.com
edge.microsoft.com
clients2.googleusercontent.com
static.edge.microsoftapp.net
self.events.data.microsoft.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
nexusrules.officeapps.live.com
fe3cr.delivery.mp.microsoft.com
stun.l.google.com
www.microsoft.com
login.live.com
copilot.microsoft.com
go.microsoft.com
edge-cloud-resource-static.azureedge.net
update.googleapis.com
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaagb6jmmcovb6saaaaaaay%3d
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:pdd71ohkezdwymxm68sfnefjkl01ijrsno6pw6_ktns&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
http://64.89.161.119:751/download
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d237%2526e%253d1
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://update.googleapis.com/service/update2/json?cup2key=14:mkfzzbaaocbobkla2l5hjzxzna4ge9jnbhwvfujxvra&cup2hreq=4da77628f6c723cc1df742496491841e7d81e5b5fa7cc5b937c4f4827900442d
https://aefd.nelreports.net/api/report?cat=bingserp
https://www.bing.com/api/shopping/v1/user/shoppingsettings?enabledservicefeaturesv2=edgeserverux.shopping.cashbackeumarkets,edgeserverux.shopping.msedgeshoppingcashbackdismisstimeout2s
https://clients2.googleusercontent.com/crx/blobs/auu14h9lifl_xdfovyc6ev9d9ia6qcy2fpggd1uevuk_yoqwcsmd13fexvuvu2cn93z41_hou8y7vuivvhjkvqkxhviwy8eqaszi6uvsh8cwzz02zvegbus0d2hnwvroeqeaxlka5cc_zznn-sn4gcvn46um6ojs-psr/ghbmnnjooekpmoecnnnilnnbdlolhkhi_1_108_1_0.crx
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 1016
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 3867
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 8607
comments 0

Moonrise RAT: The Go-Based Trojan That Steals Credentials, Hijacks Crypto Wallets, and Watches Through Your Webcam

Key Takeaways

  1. Moonrise is a newly discovered Go-based RAT that achieved zero detections at launch, demonstrating a significant gap between static antivirus coverage and real-world threat behavior.
  2. Its capabilities include credential theft, keylogging, clipboard hijacking (including cryptocurrency clipping), webcam and microphone access, screen streaming, remote command execution, UAC bypass, and rootkit functionality — making it one of the more feature-complete RATs discovered in 2025-2026.
  3. The malware communicates via WebSocket protocol, blending C2 traffic into normal HTTPS activity and bypassing many traditional network monitoring tools.
  4. Organizations in financial services, healthcare, technology, government, and legal sectors face the highest exposure, given Moonrise's focus on credential theft and silent surveillance.
  5. ANY.RUN's Threat Intelligence Lookup allows SOC and MSSP teams to instantly enrich any indicator associated with Moonrise — hash, IP, domain, or URL — and pivot to related infrastructure and samples, collapsing the triage cycle from hours to minutes.

destinationIP:"193.23.199.88".

Domain linked to Moonrise in TI Lookup Domain linked to Moonrise with context data and malware analyses

  1. ANY.RUN's Interactive Sandbox remains the most direct way to confirm whether a suspicious file behaves like Moonrise, providing full behavioral visibility including process trees, network connections, and TTPs in minutes.

View analysis

Moonrise RAT malware analysis in Interactive Sandbox Moonrise RAT fresh sample analysis in Interactive Sandbox

  1. Behavioral analysis, not static signatures, is the only reliable way to detect Moonrise-class threats. Organizations relying solely on reputation-based tools are flying blind against this threat category.

What is Moonrise RAT Malware?

Moonrise is a full-featured remote access trojan engineered for stealth, persistence, and broad operational control. Identified by ANY.RUN researchers in early 2026, it was found to operate without triggering a single vendor alert on VirusTotal at the time of analysis — meaning it could steal credentials, execute remote commands, and establish persistent backdoor access while security teams had no indication anything was wrong.

The selection of Go as a development language is a deliberate technical choice: Go produces self-contained binaries with no external runtime dependencies, supports cross-platform compilation, and is notoriously difficult for traditional AV engines to fingerprint because its compiled output does not resemble the patterns associated with older malware codebases.

The malware's C2 communication is conducted via the WebSocket protocol, enabling it to masquerade as ordinary HTTPS traffic and blend into normal network activity. From the moment of infection, Moonrise establishes a persistent, bidirectional channel with its operator infrastructure — initiating a session handshake before any vendor signatures have been published.

Its command set is remarkably broad. Moonrise supports session management, full host reconnaissance, active command execution, credential harvesting, live user monitoring, privilege manipulation, and disruptive functions (fun_bsod, fun_shutdown, fun_restart, voltage_drop). The malware also supports lifecycle management via update and uninstall commands, allowing operators to modify or remove the implant after use.

This depth of functionality places Moonrise well above simple backdoors. It is a comprehensive offensive toolkit capable of supporting everything from initial access and reconnaissance to data exfiltration and secondary payload delivery — all while staying beneath static detection thresholds.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

How Moonrise RAT Threatens Businesses and Organizations

Moonrise presents risk across multiple dimensions:

Operational Risk

  • Long dwell time due to stealthy C2,

  • Lateral movement before detection,

  • Privilege escalation and domain compromise.

Financial Risk

  • Data theft leading to regulatory fines,

  • Ransomware deployment as secondary stage,

  • Business interruption.

Strategic Risk

  • Intellectual property exfiltration,

  • Access resale in underground markets,

  • Supply chain infiltration.

Moonrise is particularly dangerous because it often acts as an access broker tool. It may not be the final payload. It is the key that opens the vault for other actors.

Victimology: Vulnerable Industries and Sectors

Based on what Moonrise can do and how similar Go-based RATs have been deployed historically, the following sectors face elevated risk:

  • Credential theft, clipboard monitoring (including cryptocurrency wallet address hijacking via clipper_get_addresses and clipper_set_address), and keylogging make financial institutions especially attractive targets.

  • Healthcare remains the most breached industry globally, with breach costs averaging $10.3 million per incident. Moonrise's ability to exfiltrate data silently makes it well-suited for targeting patient records, insurance data, and pharmaceutical IP.

  • Technology and SaaS companies, as organizations that manage infrastructure for third parties, are high-value targets for initial access brokers and nation-state actors. A compromised DevOps endpoint can cascade into supply chain compromise.

  • Legal and professional services handling sensitive client data — contracts, litigation strategy, M&A intelligence — are highly vulnerable to the kind of silent exfiltration Moonrise enables.

  • Moonrise's webcam, microphone, and screen streaming capabilities align with espionage use cases. Government and defense contractors that work with sensitive national security data are natural targets.

  • As RAT activity in manufacturing surged 174% for comparable tools in Q4 2025 (per ANY.RUN data), operational technology environments and industrial control systems represent a growing attack surface. Manufacturing and critical infrastructure are at risk.

  • Decentralized IT environments, legacy systems, and limited security budgets make universities and research institutions particularly vulnerable to low-detection threats like Moonrise.

How Can Businesses Proactively Protect Against Moonrise

The defining challenge Moonrise poses is temporal: it acts before defenses can recognize it. Proactive threat intelligence tools address exactly this gap.

ANY.RUN Threat Intelligence Feeds provide a continuous stream of fresh, validated indicators derived from analysis sessions by 600,000+ security professionals across 15,000+ organizations. For Moonrise specifically, TI Feeds would surface the C2 IP (193.23.199.88) and associated file hashes before your internal systems encounter them, allowing defensive infrastructure to block the threat at the perimeter rather than detect it post-compromise.

TI Feeds benefits and integration TI Feeds: benefits, data sources, integration options

When an alert does fire — an unusual outbound connection, a suspicious process spawned by svchost.exe, or an unexpected file execution — Threat Intelligence Lookup allows analysts to instantly pivot on any observable indicator. A hash, IP, domain, or URL can be cross-referenced against the ANY.RUN database to retrieve related sandbox analyses, historical sightings, linked infrastructure, and associated malware families.

sha256:"ed5471d42bef6b32253e9c1aba49b01b8282fd096ad0957abcf1a1e27e8f7551".

File hash observed in Moonrise samples File hash observed in Moonrise samples

Other Defensive Measures

  • Deploy behavioral EDR solutions capable of detecting anomalous process trees, unexpected UAC bypass attempts, and unauthorized access to audio/video hardware.

  • Implement network segmentation and egress filtering to limit the blast radius of any single compromised endpoint.

  • Enforce multi-factor authentication across all critical systems to reduce the value of stolen credentials.

  • Conduct regular threat hunting exercises focused on weak signals: unexpected WebSocket connections, svchost.exe spawning cmd.exe, and new scheduled tasks or registry run keys.

  • Use ANY.RUN's Interactive Sandbox to safely analyze suspicious files and URLs in a controlled environment before they reach production systems.

  • Establish a patch cadence and ensure endpoint security software is current, reducing the attack surface Moonrise can exploit during initial access.

How Moonrise RAT Gets in the System and Functions

Like most RATs, Moonrise relies on social engineering to achieve initial execution.

  • Malicious document attachments: PDF, Word, or Excel files containing macros or embedded exploits that trigger payload download and execution.

  • Executable masquerading: Binaries disguised as legitimate software installers, game cracks, or utility tools, distributed through phishing emails, fake download pages, or social media.

  • Archive files: ZIP, RAR, or ISO containers that bypass email filtering and deliver the payload when extracted and executed by the user.

  • Script-based delivery: PowerShell or batch scripts that download and execute Moonrise from remote infrastructure, often triggered by document macros.

  • Spear-phishing: Targeted emails crafted to impersonate trusted contacts or internal IT communications, increasing the likelihood of user execution.

Moonrise operates through a structured, session-oriented command loop. Its operation can be broken into seven phases:

Phase 1 — Session Establishment: The malware initiates contact with its C2 server via WebSocket protocol. It sends client_hello and connected signals, then maintains the session with periodic ping/pong heartbeats. This phase completes silently, with no user-visible behavior.

Phase 2 — Host Reconnaissance: The operator requests a comprehensive picture of the victim environment via process_list, file_list, monitors_list, webcam_list, and screenshot commands.

Phase 3 — Active Control: Using cmd, process_kill, file_upload, file_run, file_execute, file_delete, mkdir, and explorer_restart, the operator takes direct control of the endpoint — running commands, terminating security processes, uploading payloads, and modifying the file system.

Phase 4 — Credential Harvesting: The stealer module extracts credentials from browsers, applications, and system memory.

Phase 5 — Live Surveillance: Keyloggers, clipboard monitors, screen streaming, webcam capture, and microphone recording convert the endpoint into a real-time surveillance node. The clipper module can also substitute cryptocurrency wallet addresses in the clipboard, redirecting transactions to attacker-controlled wallets.

Phase 6 — Privilege Escalation and Persistence: uac_bypass allows elevation to administrator privileges. rootkit_enable installs rootkit components to hide the malware's presence. watchdog_status and protection_config ensure the malware monitors its own integrity and resists removal.

Phase 7 — Lifecycle Management: The update command allows operators to deploy new versions of Moonrise without re-infecting the host. The uninstall command cleanly removes the malware after an operation is complete — leaving minimal forensic trace.

Sandbox Analysis of Moonrise RAT Sample

You can follow the full Moonrise chain in real time, from execution to C2 control, and note the behaviors you can use for detection and triage.

View analysis

ANY.RUN sandbox revealing Moonrise full attack chain ANY.RUN sandbox revealing Moonrise full attack chain

Within minutes of execution, Moonrise established outbound communication and began responding to operator-driven commands. What looked harmless in static checks immediately revealed interactive control once behavior was observed.

1. Session Registration and Persistent Communication

The communication begins with the commands that handle client identification and keep the WebSocket session alive. This confirms that the infected system is actively connected and ready to receive instructions. At this stage, traditional static checks still show nothing suspicious. But behaviorally, the endpoint is already under remote control.

C2 communication overview of Moonrise RAT C2 communication overview of Moonrise RAT

2. Visibility Into the Host Environment

Once the session is established, the operator starts requesting information about the system that allows to inspect running processes, review directory structures, identify connected displays, and check for available multimedia devices. Even when screen capture fails in a headless environment, the attempt itself signals active operator-driven interaction.

YARA rule match confirming screenshot functionality inside the Moonrise process YARA rule match confirming screenshot functionality inside the Moonrise process

3. Direct System Interaction and Control

Operators can run system commands remotely, terminate selected processes, upload additional payloads, execute them, modify directories, and restart system components.

svchost.exe spawning cmd.exe to execute system commands inside the ANY.RUN sandbox svchost.exe spawning cmd.exe to execute system commands inside the ANY.RUN sandbox

4. Credential Access and Data Extraction

Functions like stealer, keylogger_logs, clipboard_history enable collection of stored credentials, extracted files, logged keystrokes, and clipboard content. If sensitive data is copied between applications, such as passwords or financial details, it becomes accessible to the operator.

5. Active User Monitoring

Another set of commands allows malefactor to monitor user input, track clipboard changes, capture screen content, and access audio or video devices.

Moonrise RAT checks for available and operational camera hardware before attempting capture Moonrise RAT checks for available and operational camera hardware before attempting capture

6. Privilege and System-Level Capabilities

Moonrise also contains commands related to privilege handling and system configuration. These suggest support for privilege manipulation, system configuration changes, and persistence-related behavior. While not all commands may be triggered in every session, their presence indicates extended control options.

7. Lifecycle Management and Disruption

Lifecycle management functions let operators modify or remove the deployed version of the malware. This indicates support for maintaining or adjusting the infection over time.

Gathering Threat Intelligence on Moonrise RAT Malware

Even for zero-day threats like Moonrise, TI Lookup surfaces all sandbox sessions in which associated infrastructure appeared, giving teams visibility into the timeline and scope of the threat. Confirmed Moonrise indicators (e.g., C2 IP 193.23.199.88) can be used as pivots to discover related samples, associated domains, and attacker infrastructure clusters, enabling proactive hunting rather than reactive response.

TI Lookup displays sandbox analyses related to the IP address used in the Moonrise attack TI Lookup displays sandbox analyses related to the IP address used in the Moonrise attack

Rich context around any indicator helps Tier-1 analysts quickly distinguish genuine Moonrise-related activity from noise, reducing unnecessary escalations and improving MTTR.

Lookup integrates with existing SIEM, SOAR, and ticketing systems, allowing enrichment workflows to be automated and embedded in existing SOC processes.

MSSPs can leverage TI Lookup to investigate indicators across client environments and share relevant intelligence, improving coverage without duplicating manual research effort.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Moonrise is a case study in what makes modern malware genuinely dangerous: not raw power, but strategic invisibility. Its Go-based architecture, WebSocket C2, zero static detections at launch, and comprehensive command set combine to create a threat that can operate undetected for extended periods — stealing credentials, establishing persistence, staging payloads, and surveilling users while security teams have no indication anything is wrong.

For companies, the consequence is not just a technical incident but a business crisis: extended dwell time, stolen credentials, potential ransomware staging, regulatory exposure, and reputational damage. The financial services, healthcare, technology, legal, and government sectors face the highest exposure, but no industry is immune to a RAT that can bypass static defenses so effectively.

The defensive answer is not more signatures — it is faster behavioral clarity. ANY.RUN's Threat Intelligence Feeds and TI Lookup together address Moonrise's core advantage: they surface new infrastructure and behavioral indicators before static detection catches up, enable rapid enrichment and pivot during triage, and support proactive hunting to catch the next Moonrise-class threat before it becomes a costly incident.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

MassLogger screenshot
MassLogger
masslogger
MassLogger is a credential stealer and keylogger first identified in April 2020. It has been actively used in cyber campaigns to exfiltrate sensitive information from compromised systems. It is designed for easy use by less tech-savvy actors and is prominent for the capability of spreading via USB drives. It targets both individuals and organizations in various industries, mostly in Europe and the USA.
Read More
JOMANGY screenshot
JOMANGY is a PHP webshell and backdoor family targeting vulnerable FreePBX servers. It is designed to establish long-term access to compromised VoIP infrastructure, enable toll fraud, and survive remediation attempts through multiple self-reinforcing persistence mechanisms. Unlike many traditional webshells, JOMANGY employs a highly resilient architecture that can automatically restore itself even after partial removal.
Read More
Latrodectus screenshot
Latrodectus
latrodectus
Latrodectus is a malicious loader that is used by threat actors to gain a foothold on compromised devices and deploy additional malware. It has been associated with the IcedID trojan and has been used by APT groups in targeted attacks. The malware can gather system information, launch executables, and detect sandbox environments. It uses encryption and obfuscation to evade detection and can establish persistence on the infected device.
Read More
Octo screenshot
Octo
octo coper
Octo malware, also known as ExobotCompact or Coper, is a sophisticated Android banking trojan that has evolved from earlier malware family Exobot. It poses a significant threat to financial institutions, mobile users, and enterprise networks.
Read More
DoubleTrouble screenshot
DoubleTrouble
doubletrouble
DoubleTrouble is a new-generation Android malware designed to quietly infiltrate mobile devices, harvest sensitive data, hijack financial operations, and maintain long-term persistence. Unlike commodity Android trojans, it blends advanced evasion, dual-stage infection, and dynamic payload updates, making it a rising mobile threat for both consumers and organizations.
Read More
Interlock screenshot
Interlock
interlock
Interlock is a relatively recent entrant into the ransomware landscape. First identified in 2023, it's a multi-functional malware strain used in ransomware-as-a-service (RaaS) operations.
Read More