Decoy Mutex

By Madhukar Raina on 04 Apr 2025 @ Blackhat : Arsenal
πŸ’» Source Code πŸ”— Link
ransomware
Focus Areas: Malware Analysis
This Tool Demo covers following tools where the speaker has contributed or authored
DECOY_MUTEX

Abstract

A Windows tool for creating decoy mutexes (Fake Infection Markers) associated with ransomware simulations. Ransomware checks for the presence of its related mutex to determine whether the system is already infected. It doesn’t infect the system if it locates the mutex.