#TFlower
Malware/Tool
2021-03-23 • Lazarus Group’s MATA Framework Leveraged to Deploy TFlower Ransomware
TFlower is ransomware deployed during the encryption and extortion stage of a double-extortion intrusion investigated by Sygnia. The attacker used a previously undocumented variant of the modular MATA framework to distribute and execute TFlower inside the victim environment. MATA provided the post-compromise mechanism that moved the operation toward ransomware deployment, while TFlower performed the destructive business-impact phase. The activity showed TFlower operating within a broader intrusion framework rather than as an isolated ransomware infection and had assessed connections involving Lazarus-linked operations.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days