New 01Flip Ransomware Targets Both Windows and Linux Systems
## Cybersecurity: Emergence of 01flip Ransomware
Cybersecurity: Emergence of 01flip Ransomware
Security researchers at Palo Alto Networks Unit 42 have identified a new ransomware family, 01flip, which signifies a notable shift in malware development tactics.
First discovered in June 2025, this threat is entirely written in Rust, a modern programming language that enables cross-platform compatibility. It currently targets a limited set of victims in the Asia-Pacific region.
The discovery highlights the trend of cybercriminals adopting advanced programming languages to expand their operational reach across diverse systems and platforms.
Technical Architecture and Capabilities
The 01flip ransomware demonstrates sophisticated multi-platform functionality by leveraging Rust's cross-compilation capabilities.
Both Windows and Linux variants share substantially identical core functionality, utilizing the same dependencies and library versions with only minor architecture-specific variations.
The ransomware implements several key operational capabilities, including:
First discovered in June 2025, this threat is entirely written in Rust, a modern programming language that enables cross-platform compatibility.
Comprehensive drive enumeration Mass ransom note creation across accessible directories File encryption using AES-128-CBC algorithms combined with RSA-2048 key encryption Automated self-deletion procedures to remove forensic evidence
Defense evasion techniques include the use of low-level APIs and system calls that blend seamlessly with legitimate operating system activity. Additionally, critical strings within the ransomware binary, including ransom note content, extension lists, and RSA public keys, are encoded and decrypted only at runtime.
Both variants implement anti-sandbox mechanisms, with samples containing the filename string "01flip" proceeding directly to indicator removal without executing file encryption routines.
During the technical analysis, researchers discovered a "lockbit" extension in 01flip's file encryption exclusion list, suggesting potential overlap between CL-CRI-1036 operators and the LockBit ransomware group.
No substantive technical connections between the two ransomware families have been identified beyond this anomaly, and further investigation is required to establish any definitive operational relationships.
Organizations are advised to implement comprehensive endpoint detection and response solutions capable of identifying Rust-compiled malware behaviors and monitor for indicators associated with CL-CRI-1036 activity.
Palo Alto Networks customers benefit from protection through Advanced WildFire, Cortex XDR, XSIAM, and Cortex Xpanse platforms. Organizations suspecting compromise should contact specialized incident response teams immediately for threat investigation and remediation assistance.
Based on reporting by GBHackers.
