RegretLocker is a recently-discovered ransomware family that sports a multitude of modern features. It has the ability to terminate any process that may interfere with the encryption process, partially achieved via the Windows Restart Manager API. It can encrypt all the usual file types including virtual machine images, as well as deleting VSS copies (through multiple approaches). Current analysis shows some ability to scan for additional victims via SMB. Encrypted files are marked with a “.mouse” extension. Victims are instructed, via ransom note, to contact the attacker via email, as opposed to a TOR-based payment portal.
SentinelOne PartnerOne - America's 2025
⛳️ Last week in Pebble Beach the America's best cybersecurity partners came together for our annual PartnerOne summit. Check out…
Just a Sec: Cybersecurity Unfiltered—Fast, Frank, and From the Front Lines
Welcome to the first-ever Just A Sec, a no-holds-barred, quick-fire monthly livestream. It’s cybersecurity like you’ve never heard it before—unfiltered,…
See how our intelligent, autonomous cybersecurity platform harnesses the power of data and AI to protect your organization now and into the future.