The Containment Era is here. →Explore

Executive Summary

In June 2025, a financially motivated cybercrime group tracked as CL-CRI-1036 launched targeted ransomware attacks using a new cross-platform strain called 01flip—written in Rust—against select organizations in the Asia-Pacific region. Initial access appears to have been gained by exploiting known vulnerabilities in internet-facing applications, including CVE-2019-11580, followed by lateral movement and mass deployment of ransomware payloads across Windows and Linux systems. The attackers demanded payment in Bitcoin and posted evidence of stolen data on dark web forums, impacting at least one critical infrastructure operator and resulting in operational disruption and data exposure.

This incident highlights the rapid evolution of ransomware, with threat actors increasingly adopting modern development languages for advanced evasion. The emergence of 01flip demonstrates the ongoing risk posed by zero-day exploitation, inadequate segmentation, and cross-platform malware, underscoring the need for organizations to prioritize proactive threat detection and incident response capabilities.

Why This Matters Now

The 01flip campaign exemplifies a new wave of multi-platform ransomware leveraging modern programming languages and hands-on intrusion techniques to bypass traditional security controls. Rapid adoption of such tools by cybercriminals means organizations must urgently update prevention and detection measures, especially amid heightened ransomware activity and increasing regulatory scrutiny.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attack highlighted failures in patching known vulnerabilities, insufficient segmentation, and gaps in threat detection, all critical for compliance under frameworks like HIPAA, PCI DSS, and NIST CSF.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust controls such as network segmentation, egress enforcement, encrypted traffic inspection, and threat detection would have reduced initial exposure, hampered lateral movement, and limited ransomware spread or data leakage within the environment. Applying CNSF-aligned capabilities across hybrid and multi-cloud infrastructure layers disrupts attacker workflows and detects abnormal behaviors early in the kill chain.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Malicious inbound exploits would be blocked at the perimeter.

Privilege Escalation

Control: Threat Detection & Anomaly Response

Mitigation: Suspicious privilege escalation and credential dumping activity are detected rapidly.

Lateral Movement

Control: Zero Trust Segmentation

Mitigation: Lateral movement pathways are minimized or blocked entirely.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Known C2 traffic or threat signatures are detected and blocked in real-time.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Unapproved outbound connections are detected and prevented.

Impact (Mitigations)

Rapid ransomware propagation is identified and contained.

Impact at a Glance

Affected Business Functions

  • Email Communications
  • File Storage
  • User Authentication
Operational Disruption

Estimated downtime: 5 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive user credentials and internal communications due to unauthorized access and data encryption by ransomware.

Recommended Actions

  • Enforce strict zero trust segmentation and microsegmentation across all cloud and on-prem workloads to prevent lateral movement by malware or tools like Sliver.
  • Deploy cloud-native firewalls and tightly restrict inbound and outbound connectivity to minimize attack surface and block exploitation attempts.
  • Implement real-time inline IDS/IPS (e.g., Suricata) with threat signature updates to detect and disrupt malicious command-and-control and exploitation activity.
  • Continuously monitor internal traffic (east-west) for anomalous patterns, including credential access and ransomware propagation, and automate alerting/response.
  • Apply robust egress filtering and outbound policy enforcement to detect and block potential data exfiltration and reduce ransomware aftermath risks.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image