COLOSSUS

COLOSSUScolossus

Description

Colossus ransomware was first observed in September 2021, when ZeroFox researchers uncovered the variant attacking a U.S.-based automotive group. It employs a double-extortion model, using Themida packing and sandbox evasion to disable defenses and deliver encrypted payloads. Victims are urged to visit a support site—hosted at a domain like colossus.support—to negotiate payment, or face large-scale data dumps and increasing ransom amounts tied to countdown timers. Operators demonstrated familiarity with RaaS playbooks, drawing architectural parallels to groups like EpsilonRed, BlackCocaine, and REvil/Sodinokibi.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
Zeoticus
Software
cyclops
Software
cactus
Software
Midas
Software
Coom
Software
BigBossHorse
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.