: While initially a 64-bit Windows console application written in C++, it has since evolved to include Linux variants targeting VMware ESXi virtual machines.
: The malware both encrypts and exfiltrates data, threatening to leak sensitive information on a public "leak site" if the ransom is not paid.
: Provides a breakdown of the executable's behavior, IOCs, and background on the threat actors.
For an "interesting paper" or in-depth technical analysis, you can refer to the study . Other key technical resources include: