SYMBOLCOMMON_NAMEaka. SYNONYMS
win.ymir (Back to overview)

Ymir


According to Kaspersky, this malware sticks out as performing a large set of operations in memory with the help of the malloc, memmove and memcmp function calls.

References
2024-11-11KasperskyAshley Muñoz, Cristian Souza, Eduardo Ovalle
Ymir: new stealthy ransomware in the wild
Ymir

There is no Yara-Signature yet.