CORVUS WOLF
Financially motivated · ransomware-as-a-service
Operates the Kryptline encryptor with 40–60 affiliates. Gains access through edge-device exploitation and callback phishing, dwells for a median of 4.2 days, and exfiltrates before encrypting. Notable for disabling backups through the hypervisor rather than the guest.
- Primary targets
- Manufacturing, healthcare, professional services in North America and Western Europe
- Tracked techniques
- 73 ATT&CK techniques · 61 Guardian detections mapped