6 min read
Static Analysis of a Ryuk Ransomware Sample (Hermes Variant)
Static reverse engineering of two 32-bit PE binaries identified as Ryuk ransomware (Hermes variant). Covers the dropper/loader and the encryption payload, including persistence, process injection, and VSS deletion behavior.
Read full article