#TFlower

Malware/Tool

2021-03-23 • Lazarus Group’s MATA Framework Leveraged to Deploy TFlower Ransomware

TFlower is ransomware deployed during the encryption and extortion stage of a double-extortion intrusion investigated by Sygnia. The attacker used a previously undocumented variant of the modular MATA framework to distribute and execute TFlower inside the victim environment. MATA provided the post-compromise mechanism that moved the operation toward ransomware deployment, while TFlower performed the destructive business-impact phase. The activity showed TFlower operating within a broader intrusion framework rather than as an isolated ransomware infection and had assessed connections involving Lazarus-linked operations.

Tagged Reports

« Back