<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Double-Extortion on CuraSec</title><link>https://curasec.metacog.co.kr/tags/double-extortion/</link><description>Recent content in Double-Extortion on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 11 Aug 2026 11:54:43 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/double-extortion/index.xml" rel="self" type="application/rss+xml"/><item><title>DeadLock Ransomware: Rust-Based Encryptor with Decentralized C2</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-deadlock-ransomware-breaking-down-a-rust-based-encryptor-wit/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-deadlock-ransomware-breaking-down-a-rust-based-encryptor-wit/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No KEV, PoC, or exploited CVE tied to initial access; architectural details on Rust-based encryptors and decentralized comms are useful for understanding modern ransomware design but require no immediate system change.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections for DeadLock TTPs (Rust encryptor behavioral indicators, decentralized negotiation infrastructure patterns); review the Microsoft post for any ATT&amp;amp;CK mappings and stage them as hunt queries this quarter.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Useful context on an emerging double-extortion operator for future board or IR briefings, but no named victim sector or vendor exposure requiring immediate leadership action.&lt;/li>
&lt;/ul></description></item></channel></rss>