How Sinobi Ransomware Encrypts Files and Destroys Backups

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

How Sinobi Ransomware Encrypts Files and Destroys Backups

Sinobi is a ransomware strain first observed in July 2025, likely a rebrand of Lynx ransomware (active since 2024). It operates as Ransomware-as-a-Service. It encrypts files using Curve-25519 + AES-128-CTR, appends a .SINOBI extension, and drops a README.txt ransom note. Attackers demand negotiation within 7 days and replace the desktop wallpaper with the ransom note.

Article Link: How Sinobi Ransomware Encrypts Files and Destroys Backups

1 post - 1 participant

Read full topic



Malware Analysis, News and Indicators - Latest topics
Next Post Previous Post