The ransomware, dubbed “Ymir”, employs advanced stealth and encryption methods. It also selectively targets files and attempts to evade detection.
Uncommon memory manipulation techniques for stealth. Threat actors leveraged an unconventional blend of memory management functions – malloc, memmove, and memcmp – to execute malicious code directly in the memory.