Mortalkombat

Malware updated a month ago (2024-11-29T14:52:03.147Z)
Download STIX
Preview STIX
MortalKombat is a new ransomware family that was discovered by Talos earlier this year. It was generated by the leaked Xorist ransomware builder, a type of malware that has been in existence since 2016. MortalKombat has been used by an unidentified threat actor since December 2022 to target individuals and smaller companies. This malicious software infiltrates systems through suspicious downloads, emails, or websites, often without the user's knowledge, and then encrypts critical system details, rendering the affected system inoperable. The MortalKombat ransomware is particularly notable for its focus on cryptocurrency wallets, aiming to either steal or demand payments in virtual currency. It has been deployed alongside another malware called Laplas Clipper in a financially motivated campaign. The Laplas Clipper malware is a clipboard stealer designed to trick victims into performing fraudulent cryptocurrency transactions. This dual attack strategy allows the threat actors to extort money from victims by offering a decryptor for the encrypted files and simultaneously hijacking crypto transactions. The emergence of MortalKombat, along with other new ransomware families like RA Group, RTM Locker, ESXiArgs, Chaos 4, represents a continued evolution of cyber threats. These malware campaigns have also started to use ZIP archives as a method of deployment, further expanding their potential impact. However, there is some hope for those affected; researchers have released a MortalKombat ransomware decryptor, offering a possible solution to users whose systems have been compromised.
Description last updated: 2024-05-04T16:43:59.966Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Xorist is a possible alias for Mortalkombat. **Executive Summary: Threat Actor Xorist** Xorist is a notable threat actor associated with ransomware attacks, particularly known for its development and distribution of the Xorist ransomware variant. Initially identified in 2020, Xorist has evolved through multiple iterations, often leveraging so
4
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Ransomware
Malware
Wiper
Payload
Loader
Ransom
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Mortalkombat Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
BankInfoSecurity
2 years ago
InfoSecurity-magazine
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
InfoSecurity-magazine
2 years ago
CERT-EU
a year ago
CERT-EU
2 years ago
CERT-EU
2 years ago
InfoSecurity-magazine
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
Securityaffairs
2 years ago
Bitdefender
2 years ago