Skip to main content
← Back to Demos
Malware beginner · 15 min

Sandbox Observes Mass File Encryption and Ransom Note Behavior

The threat group tracked as Silent Ransom is escalating extortion attacks against US law firms, exfiltrating sensitive client data and threatening public disclosure after breaching networks through phishing, credential theft, and VPN exploitation. Once inside, ransomware operators typically deploy an encryptor that walks the filesystem, encrypting documents with a fast symmetric cipher, appending an extension, and dropping ransom notes across affected folders. The danger is that the encryptor is often a fresh build that no signature has seen. This demo uses a benign encryptor that only touches files inside a dedicated test directory, so nothing outside the sandbox is affected. The Adaptive Sandbox detonates the sample in an isolated Windows environment, observes the mass-encryption and ransom-note behaviors, and reports the malicious activity with behavioral indicators — no signature required.

Attack Technique

Ransomware file-encryption behavior

MITRE ATT&CK

T1486 ↗

Platforms

linuxmacoswindows

File Types

.sh

MetaDefender Capabilities

Adaptive Sandbox

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---