YourCyanide, a new and sophisticated ransomware variant that integrates documents into PasteBin, Discord, and Microsoft Office

Attack process

The diagram shown below describes the infection process that YourCyanide follows:


The continuous use of obfuscated scripts makes the task of identifying malicious YourCyanide payloads very difficult, which is very favorable for threat actors. Although this is not a completely new technique, the way the operators of this malware variant use it makes the obfuscation process much more effective.



