We’ve got you covered. Every session is here, ready to stream on demand.
Cohesity REDLab is the data protection industry’s only dedicated source of actionable intelligence on how malware interacts with backup infrastructure. This team of experts operates an air-gapped facility where live malware is executed against production-grade Cohesity DataProtect and Cohesity NetBackup deployments. By analyzing sophisticated malware, researchers gain deeper insight into emerging techniques and tactics. These findings help drive the design and enhancement of advanced threat detection and scanning technologies, strengthening defences against ransomware attacks.
This newsletter provides monthly updates on the most impactful ransomware strains evaluated in REDLab, along with comprehensive findings concerning detection and recovery procedures.
REDLab incorporates both Cohesity DataProtect and Cohesity NetBackup to conduct extensive testing against malware and sophisticated cyberattacks. Through live malware execution, real-world exploit detonation, and modern attack techniques, REDLab evaluates the performance of Cohesity solutions under authentic attack conditions. Its air-gapped environment enables comprehensive threat assessment in a controlled setting. REDLab testing is guided by the following principles:
During this month, the malware strains listed below were intentionally detonated to evaluate product efficacy of Cohesity DataProtect and NetBackup.
|
Strain Details |
SHA-256 Hash |
|---|---|
|
Name: KryBit |
dab06e47581b87c21699bb1126b7cb2370cf86d069ad25b9b86cff8e450d7e29 |
|
Name: Zawoo |
dd21e22e2c4fffc5939dc6e42ee42ed497138d17245b59dcf4b0aca9739e337e |
|
Name: The Gentlemen |
51b9f246d6da85631131fcd1fabf0a67937d4bdde33625a44f7ee6a3a7baebd2 |
|
Name: DeadLock |
3c1b9df801b9abbb3684670822f367b5b8cda566b749f457821b6481606995b3 |
KryBit Ransomware
|
Technique Name |
MITRE ATT&CK ID |
Tactic(s) |
|---|---|---|
|
Data Encrypted for Impact |
T1486 |
Impact |
|
Data Destruction |
T1485 |
Impact |
|
Process Injection |
T1055 |
Defense Evasion, Privilege Escalation |
|
Abuse Elevation Control Mechanism |
T1548 |
Defense Evasion, Privilege Escalation |
|
Masquerading |
T1036 |
Defense Evasion |
|
Hide Artifacts |
T1564 |
Defense Evasion |
|
Hidden Window |
T1564.003 |
Defense Evasion |
|
Indirect Command Execution |
T1202 |
Defense Evasion |
|
Application Layer Protocol |
T1071 |
Command and Control |
|
Data Staged |
T1074 |
Collection |
|
File and Directory Discovery |
T1083 |
Discovery |
|
Process Discovery |
T1057 |
Discovery |
|
System Information Discovery |
T1082 |
Discovery |
|
System Owner/User Discovery |
T1033 |
Discovery |
Note: Above table contains a curated subset of techniques prioritized for monitoring and response.
KryBit was selected for this month's report on the strength of its sustained activity and growing regional relevance. The group has accumulated roughly 147 confirmed victims to date, including a peak of 36 disclosures in August 2026 alone — an average of about 24 per month. Targeted sectors span manufacturing, healthcare, construction, transportation, financial services, education, government and technology.
KryBit is a 32-bit Windows PE payload (GUI subsystem) that was scored at ‘Critical’ severity level under REDLab analysis. Static signatures matched the Babuk code lineage, while its runtime behaviour and the recovery artifacts it writes align with the Sodinokibi/REvil instruction-file pattern, indicating a payload assembled from well-established ransomware building blocks rather than an entirely novel family.
Before encrypting, the sample profiles the host extensively. It queries the keyboard layout, system locale and language registry keys - resolves volume mount points and historical removable and network drive entries, reads the volume serial number and physical hardware ID for victim profiling, enumerates running processes and checks its own token for administrator or UAC elevation status. A date-expiration check and a SetUnhandledExceptionFilter anti-debug hook were both observed, and the process created a hidden window to keep the activity off-screen.
Encryption is broad and destructive. The strain systematically walks user directories with wildcards, opens a large number of files requesting WRITE or DELETE access, and strips file attributes to defeat read-only protection before writing. Every affected file is renamed with a “.KRYBIT” extension, and REDLab analysis recorded mass file deletion and overwriting of existing files alongside the encryption activity. A single ransom note filename, “RECOVER-README”, is copied across every affected directory, and the Recycle Bin is manipulated during the run.
For command and control and anti-recovery, KryBit issued HTTP requests carrying features characteristic of malware traffic, including a request to a commonly exploitable directory path, and generated network activity that fell outside the monitored API log. It also attempted to delete or modify volume shadow copies and invoked Windows utilities to carry out parts of the routine indirectly. The ransom note lists four Tor blog addresses and asserts that confidential and sensitive data was exfiltrated before encryption, confirming a double-extortion posture.
Figure 1: Victim files following detonation, each appended with the “.KRYBIT” extension.
Figure 2: The “RECOVER-README” ransom note confirming encryption and listing the attacker’s Tor blog addresses.
Both DataProtect and NetBackup delivered successful VMware backup and recovery following the attack. DataProtect VMware backup operations remained unaffected throughout. NetBackup's Image Entropy anomaly detection actively identified unusual deviation in VMware backup job attributes demonstrating its threat detection capabilities working as designed. VMware based backup and recovery was successful for both products.
Figure 3: KryBit Entropy Anomaly Result.
Following the ransomware attack, Rapid Threat Hunt was leveraged to proactively search for malicious activity using known SHA-256 hash and IOC associated with the KryBit ransomware. The hunt successfully identified impacted clusters, objects, and file artifacts within the environment, providing clear visibility into the scope of compromise.
Figure 4: KryBit Rapid Threat Hunt Result.
Zawoo Ransomware
|
Technique Name |
MITRE ATT&CK ID |
Tactic(s) |
|---|---|---|
|
Data Encrypted for Impact |
T1486 |
Impact |
|
Data Destruction |
T1485 |
Impact |
|
Bootkit |
T1542.003 |
Defense Evasion, Persistence |
|
Indicator Removal |
T1070 |
Defense Evasion |
|
Process Injection |
T1055 |
Defense Evasion, Privilege Escalation |
|
Abuse Elevation Control Mechanism |
T1548 |
Defense Evasion, Privilege Escalation |
|
Virtualization/Sandbox Evasion |
T1497 |
Defense Evasion, Discovery |
|
Obfuscated Files or Information |
T1027 |
Defense Evasion |
|
Software Packing |
T1027.002 |
Defense Evasion |
|
Masquerading |
T1036 |
Defense Evasion |
|
Hidden Window |
T1564.003 |
Defense Evasion |
|
Indirect Command Execution |
T1202 |
Defense Evasion |
|
OS Credential Dumping |
T1003 |
Credential Access |
|
Credentials from Web Browsers |
T1555.003 |
Credential Access |
|
Credentials In Files |
T1552.001 |
Credential Access |
|
Data from Local System |
T1005 |
Collection |
|
Data Staged |
T1074 |
Collection |
|
Native API |
T1106 |
Execution |
|
Application Layer Protocol |
T1071 |
Command and Control |
|
Replication Through Removable Media |
T1091 |
Initial Access, Lateral Movement |
Note: Above table contains a curated subset of techniques prioritized for monitoring and response.
Zawoo was selected as a newly active group whose encryption behaviour breaks conventional detection assumptions. 22 victim organisations were disclosed within roughly one month of the group's emergence. Victims span Germany, New Zealand, France, Brazil, Czech Republic, Austria and Canada, including a coordinated attack cluster in August 2026. Rather than appending a recognisable encrypted-file extension, Zawoo replaces the entire original filename and extension with random characters, and its double-extortion model includes threats to email stolen data directly to victims' customers rather than posting it to a leak site.
Zawoo is a 64-bit Windows PE console payload. It is packed, carries an unknown PE section name and a suspicious PDB path, and was the most functionally complete strain evaluated this month - combining credential theft, raw disk access and direct syscall evasion with conventional mass encryption.
The strain opens with layered environment checks: keyboard layout and locale queries, language checks via the registry, mouse-movement detection, a date-expiration timeout, service enumeration for anti-virtualization purposes and a SetUnhandledExceptionFilter anti-debug hook. It executes direct syscalls to bypass EDR and user-land API hooks, tries to unhook monitored Windows functions, and creates a process in a suspended state before reading and writing into the memory of other processes. Inter-process coordination was observed through named mutexes and shared memory mappings.
Encryption is aggressive and paired with heavy anti-recovery activity. The strain enumerates user directories with wildcards, opens a large number of files for WRITE or DELETE access, strips file attributes to bypass read-only restrictions, and both deletes and overwrites existing files. Affected files are renamed entirely - original filenames are replaced by opaque hexadecimal strings with a victim-specific extension (“.NNAOFNYS” in this detonation) - and file-extension hijacking registry keys are modified so the renamed files resolve to the attacker's handler. A ransom note, “How To Restore Your Files”, is dropped across affected directories. The sample then deleted volume shadow copies, cleared Windows event logs, created an autorun.inf file to propagate via removable media, and deleted its own binary from disk.
The ransom note is unusually long and negotiation-focused: it claims prior intrusion across the network, offers security consulting as part of the settlement, discourages contacting law enforcement, and provides a Session ID and an onionmail address for contact.
Figure 5: Victim files renamed to opaque hexadecimal strings and appended with the victim-specific “.NNAOFNYS” extension.
Figure 6: The “How To Restore Your Files” ransom note, claiming full intrusion of the network and directing the victim to a Session ID and onionmail address.
Both DataProtect and NetBackup delivered successful VMware backup and recovery following the attack. DataProtect VMware backup operations remained unaffected throughout. NetBackup's Image Entropy anomaly detection actively identified unusual deviation in VMware backup job attributes demonstrating its threat detection capabilities working as designed. VMware based backup and recovery was successful for both products.
Figure 7: Zawoo Entropy Anomaly Result.
Following the ransomware attack, Rapid Threat Hunt was leveraged to proactively search for malicious activity using known SHA-256 hash and IOC associated with the Zawoo ransomware. The hunt successfully identified impacted clusters, objects, and file artifacts within the environment, providing clear visibility into the scope of compromise.
Figure 8: Zawoo Rapid Threat Hunt Result.
The Gentlemen Ransomware
|
Technique Name |
MITRE ATT&CK ID |
Tactic(s) |
|---|---|---|
|
Data Encrypted for Impact |
T1486 |
Impact |
|
Inhibit System Recovery |
T1490 |
Impact |
|
Service Stop |
T1489 |
Impact |
|
Internal Defacement |
T1491.001 |
Impact |
|
Impair Defenses |
T1562 |
Defense Evasion |
|
Disable or Modify Tools |
T1562.001 |
Defense Evasion |
|
Clear Windows Event Logs |
T1070.001 |
Defense Evasion |
|
Obfuscated Files or Information |
T1027 |
Defense Evasion |
|
Software Packing |
T1027.002 |
Defense Evasion |
|
Process Injection |
T1055 |
Defense Evasion, Privilege Escalation |
|
Hijack Execution Flow |
T1574 |
Defense Evasion, Persistence, Privilege Escalation |
|
Command and Scripting Interpreter: PowerShell |
T1059.001 |
Execution |
|
Windows Management Instrumentation |
T1047 |
Execution |
|
System Services: Service Execution |
T1569.002 |
Execution |
|
Remote Services: SMB/Windows Admin Shares |
T1021.002 |
Lateral Movement |
|
Lateral Tool Transfer |
T1570 |
Lateral Movement |
|
Network Share Discovery |
T1135 |
Discovery |
Note: Above table contains a curated subset of techniques prioritized for monitoring and response.
The Gentlemen was selected as the largest active ransomware campaign in the current landscape. It has accumulated approximately 870 disclosed victims across 32 countries, averaging around 58 disclosures per month and peaking at 145 in August 2026. The group targets enterprise backup infrastructure directly, including backup services and Volume Shadow Copies, and uses Bring-Your-Own-Vulnerable-Driver (BYOVD) techniques to disable EDR and other security products ahead of encryption. Affected sectors include manufacturing, healthcare, financial services, government, education, retail, technology and construction.
The Gentlemen is a 64-bit Windows console payload written in Go. This strain was detonated inside the REDLab facility alongside the other strains this month; the assessment below is derived from REDLab analysis of the binary's runtime behaviour together with the ransom note and encrypted-file artifacts captured from the affected host.
The binary is packed, carries an unknown PE section name and high-entropy content, and registers a vectored exception handler to hijack execution flow. REDLab analysis also observed it creating RWX memory and probing high-memory ranges in a module-stomping pattern, along with routines that attempt to unhook or suspend the monitoring functions that detection tooling relies on - an explicit anti-analysis posture.
Cryptography is self-contained: the payload embeds ChaCha20 and AES (with AES-NI support) primitives, together with a custom hashing routine, so encryption proceeds without external dependencies. Affected files are renamed with a “.umc16h” extension, and a ransom note titled “README-GENTLEMEN.txt” is written for the victim.
The binary carries a broad operational toolkit rather than a single encryption routine. Static strings reveal command-line switches for spreading, share targeting, and “ultrafast” and “superfast” encryption modes, plus options to delay the main action and to suppress self-deletion. It embeds a PsExec service component for remote execution, builds PowerShell and WMI command lines to launch itself on remote computers, grants full access to created shares, enables the legacy SMB1 protocol, and registers a Defender process exclusion for itself. Anti-recovery and defence-impairment routines include volume shadow copy deletion, Windows event log clearing, Prefetch directory wiping, firewall modification and a large embedded kill list targeting database and enterprise application services. A “gentlemen.bmp” artifact indicates wallpaper defacement after encryption completes. The ransom note confirms double extortion. It states that confidential and business data, explicitly including NAS and cloud data, has been exfiltrated, and threatens publication on a leak site and reporting to data protection regulators. Contact is offered over Tox and Session, with a Tor leak blog and a 239-hour reveal timer.
Figure 9: Victim files following encryption, each appended with the “.umc16h” extension.
Figure 10: The “README-GENTLEMEN.txt” ransom note claiming exfiltration of NAS and cloud data, with Tox and Session contact details and a leak-site reveal timer.
Both DataProtect and NetBackup delivered successful VMware backup and recovery following the attack. DataProtect VMware backup operations remained unaffected throughout. NetBackup's Image Entropy anomaly detection actively identified unusual deviation in VMware backup job attributes demonstrating its threat detection capabilities working as designed. VMware based backup and recovery was successful for both products.
Figure 11: The Gentlemen Entropy Anomaly Result.
Following the ransomware attack, Rapid Threat Hunt was leveraged to proactively search for malicious activity using known SHA-256 hash and IOC associated with The Gentlemen ransomware. The hunt successfully identified impacted clusters, objects, and file artifacts within the environment, providing clear visibility into the scope of compromise.
Figure 12: The Gentlemen Rapid Threat Hunt Result.
DeadLock Ransomware
|
Technique Name |
MITRE ATT&CK ID |
Tactic(s) |
|---|---|---|
|
Data Encrypted for Impact |
T1486 |
Impact |
|
Service Stop |
T1489 |
Impact |
|
Create or Modify System Process |
T1543 |
Persistence, Privilege Escalation |
|
Windows Service |
T1543.003 |
Persistence, Privilege Escalation |
|
Bootkit |
T1542.003 |
Defense Evasion, Persistence |
|
Impair Defenses |
T1562 |
Defense Evasion |
|
Disable or Modify Tools |
T1562.001 |
Defense Evasion |
|
Abuse Elevation Control Mechanism |
T1548 |
Defense Evasion, Privilege Escalation |
|
Hide Artifacts |
T1564 |
Defense Evasion |
|
Masquerading |
T1036 |
Defense Evasion |
|
Application Layer Protocol |
T1071 |
Command and Control |
|
Replication Through Removable Media |
T1091 |
Initial Access, Lateral Movement |
|
Data Staged |
T1074 |
Collection |
|
Process Discovery |
T1057 |
Discovery |
|
System Information Discovery |
T1082 |
Discovery |
|
System Owner/User Discovery |
T1033 |
Discovery |
Note: Above table contains a curated subset of techniques prioritized for monitoring and response.
DeadLock was selected as an emerging threat built around novel extortion infrastructure. Between roughly 96 and 101 confirmed victims have been identified across some 40 countries, over half of them in Europe. The group operated quietly for approximately 11 months before entering the monthly victim leaderboard in second place during its first month of public disclosure. Backup and shadow copy services are named explicitly in the malware's own service-stop list, and the strain partially encrypts large files such as databases, VM images and backups while still rendering them unusable. Its extortion infrastructure is blockchain-hosted, leaving no domains or IP addresses to block or take down.
DeadLock is a 32-bit Windows PE console payload that was scored at ‘Critical’ severity level under REDLab analysis. Rather than relying on obfuscation, DeadLock distinguishes itself through persistence and service manipulation. The strain performs the now-familiar profiling sequence - keyboard layout and locale queries, language checks via the registry, token checks for administrator or UAC elevation status, volume mount point resolution, historical removable and network drive discovery, and volume serial number and hardware ID reads. It additionally queries display device information to determine whether it is running in a virtualized environment, and installs a SetUnhandledExceptionFilter anti-debug hook.
Persistence and impact are pursued in parallel. DeadLock exhibited service creation and modification techniques during the run, and the sample attempted to stop active services and terminate other processes on the host. It issued suspicious IO control codes indicative of disk enumeration or bootkit activity, and modified registry keys for file-extension hijacking so that renamed files resolve through the attacker's own handler. An autorun.inf file was created, giving the strain a route to propagate via removable media.
Encryption appends a victim-specific compound extension - “.F8C6A8.dlock” in this detonation - to every affected file, and a matching ransom note, “READ ME.F8C6A8.txt”, is dropped for the victim. After encryption the desktop wallpaper is replaced with a full-screen notice reading “Your infrastructure DeadLocked - All Files stolen and encrypted”, which also directs the victim to the note. The note itself claims military-grade encryption across documents, photos, videos and databases, offers a single-file decryption test capped at 1 MB, and accepts Bitcoin or Monero, with contact over Session.
Figure 13: The “READ ME.F8C6A8.txt” ransom note claiming military-grade encryption.
Figure 14: Desktop wallpaper replaced after encryption with a full-screen notice claiming data theft and directing the victim to the ransom note.
Both DataProtect and NetBackup delivered successful VMware backup and recovery following the attack. DataProtect VMware backup operations remained unaffected throughout. NetBackup's Image Entropy anomaly detection actively identified unusual deviation in VMware backup job attributes demonstrating its threat detection capabilities working as designed. VMware based backup and recovery was successful for both products.
Figure 15: DeadLock Entropy Anomaly Result.
Following the ransomware attack, Rapid Threat Hunt was leveraged to proactively search for malicious activity using known SHA-256 hash and IOC associated with the DeadLock ransomware. The hunt successfully identified impacted clusters, objects, and file artifacts within the environment, providing clear visibility into the scope of compromise.
Figure 16: DeadLock Rapid Threat Hunt Result.
Both DataProtect and NetBackup achieved successful VMware backup and recovery across all four ransomware strains tested this month – KryBit, Zawoo, The Gentlemen and DeadLock, demonstrating the resilience of Cohesity's solutions under real-world attack conditions.
DataProtect VMware backup operations remained unaffected throughout all tests, validating the platform's ability to maintain data protection under adverse conditions.
NetBackup's Image Entropy anomaly detection actively identified unusual deviations in VMware backup job attributes across all four strains - confirming its active threat detection capabilities working as designed. VMware based backup and recovery was successful.
Rapid Threat Hunt enabled proactive threat investigation by correlating known malicious SHA‑256 hashes and IOCs against protected environments, successfully identifying impacted clusters, objects and file artifacts.
For more information on REDLab, please visit https://cohesity.com/redlab
Start your 30-day free trial or view one of our demos.