We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Trojan:PowerShell/VSocCrypt.PA!MTB
Aliases: No associated aliases
Summary
This trojan is a detection of PowerShell script used before ransomware launch. The purpose of the script is to facilitate ransomware installation.
For information about VSocCrypt and other human-operated malware campaigns, read this blog post:
Users should take the following steps to mitigate the threat:
- Isolate the affected device from the network.
- Check for signs of lateral movement.
- Refer to Microsoft’s blog, Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself, for recommendations on building strong credential hygiene and other robust measures to defend against ransomware.
You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.