Skip to content

Hide Navigation Hide TOC

Injected Code — Remote-Key Ransomware File Encryption - ATR-2026-01896 (8e650176-47ec-5bc5-ad22-cdcb720aa625)

Detects injected code that fetches an encryption key from a remote server (requests.get(.../get_key).content) and encrypts a victim file in place with Fernet/AES/ChaCha20/Blowfish — the defining shape of ransomware. The remote-key + in-place-encrypt pair is the invariant.

Cluster A Galaxy A Cluster B Galaxy B Level
External Harms (ba500f0e-52ca-40ff-aed4-e6dbf00cca10) MITRE ATLAS Attack Pattern Injected Code — Remote-Key Ransomware File Encryption - ATR-2026-01896 (8e650176-47ec-5bc5-ad22-cdcb720aa625) Agent Threat Rules 1
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Injected Code — Remote-Key Ransomware File Encryption - ATR-2026-01896 (8e650176-47ec-5bc5-ad22-cdcb720aa625) Agent Threat Rules 1