logo

Evil_Corp__2022__S1_-SentinelLabs_SanctionsBeDamned_final_02.pdf

ID: c025011a-2025-44c4-843f-150565839d1e

STIX ID: report--c025011a-2025-44c4-843f-150565839d1e

Threat Score

80/100

Uploaded: 2026-08-14

Published Date: 2022-02-23

Last Modified Date: 2022-02-23

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
SentinelLabs provides an in-depth technical analysis linking multiple ransomware families (WastedLocker → Hades → PhoenixLocker → PayloadBIN → Cypherpunk/Macaw) to a single Evil Corp development ‘factory’, documenting strong code reuse, a shared CryptOne packer signature, overlapping infrastructure (SocGholish/Cobalt Strike C2s), TTPs for defense evasion and encryption, YARA rules, and numerous IoCs to assist detection and attribution.