Evil_Corp__2022__S1_-SentinelLabs_SanctionsBeDamned_final_02.pdf
ID: c025011a-2025-44c4-843f-150565839d1e
STIX ID: report--c025011a-2025-44c4-843f-150565839d1e
Threat Score
80/100
Uploaded: 2026-08-14
Published Date: 2022-02-23
Last Modified Date: 2022-02-23
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
SentinelLabs provides an in-depth technical analysis linking multiple ransomware families (WastedLocker → Hades → PhoenixLocker → PayloadBIN → Cypherpunk/Macaw) to a single Evil Corp development ‘factory’, documenting strong code reuse, a shared CryptOne packer signature, overlapping infrastructure (SocGholish/Cobalt Strike C2s), TTPs for defense evasion and encryption, YARA rules, and numerous IoCs to assist detection and attribution.
