Frequently Asked Questions

Threats & Attack Trends

What is Hades Locker ransomware and how does it operate?

Hades Locker is a ransomware strain that emerged in February 2021, based on Zyklon and Wildfire Lockers previously used in Kelihos botnet attacks. It targets manufacturing and business services, collects victim information, encrypts files using AES, deletes shadow copies to prevent recovery, and demands ransom payments in bitcoin via C&C servers or TOR. Victims receive ransom notes with payment instructions. Source

How did DanaBot re-emerge and what are its attack methods?

DanaBot re-emerged in late 2020 and February 2021, distributing malware disguised as VPNs, anti-virus programs, or online games. It uses two stealer components to collect browser details, system information, cryptocurrency wallets, and installs a cryptocurrency miner. DanaBot has targeted financial institutions in multiple countries. Source

What is BendyBear shellcode and why is it significant?

BendyBear is a sophisticated shellcode detected in February 2021, related to the WaterBear malware family and the BlackTech cyberespionage group. It loads directly into memory, supports file transfer, shell access, screen capture, and uses advanced obfuscation and encryption techniques, making it difficult to detect. It was used in attacks against East Asian government organizations. Source

How are phishing campaigns using Morse code obfuscation?

In February 2021, a phishing campaign was detected using Morse code to obfuscate malicious URLs in email attachments. The attack involved spoofed invoice emails with HTML attachments that decoded Morse code into JavaScript, ultimately stealing user credentials. At least eleven companies were affected. Source

Why are hospitals and businesses increasingly targeted by cyberattacks?

Due to the COVID-19 pandemic, hospitals and businesses with limited IT and cybersecurity resources have become prime targets for threat actors. Overworked hospitals and organizations with outdated software are especially vulnerable, as seen in attacks on French hospitals and companies like Trigano and Beneteau in February 2021. Source

Cymulate Platform & Features

What is Cymulate’s Immediate Threats Assessment and how does it help?

Cymulate’s Immediate Threats Assessment allows organizations to test and verify their exposure to the latest malware attacks, including Hades Locker, DanaBot, and BendyBear. It provides actionable mitigation suggestions if vulnerabilities are found, helping organizations proactively defend against current threats. Source

What are the core features of Cymulate’s Exposure Validation platform?

Cymulate’s Exposure Validation platform offers advanced security testing, custom attack chain building, continuous assessment, and validation of security posture. It provides a unified interface for threat simulation and actionable insights to improve defenses. Learn more

How does Cymulate help organizations stay ahead of emerging threats?

Cymulate continuously updates its threat simulation library and provides daily updates on new attack techniques. The platform enables organizations to simulate real-world threats, validate defenses, and receive actionable recommendations for mitigation. Source

What integrations does Cymulate support?

Cymulate integrates with a wide range of security technologies, including Akamai Guardicore, AWS GuardDuty, BlackBerry Cylance OPTICS, Carbon Black EDR, Check Point CloudGuard, CrowdStrike Falcon, Rapid7 InsightVM, SentinelOne, Wiz, and more. For a full list, visit the technology alliances and partners page.

What technical documentation is available for Cymulate?

Cymulate provides a product whitepaper, custom attacks data sheet, technology integrations data sheet, solution briefs, and analyst reports. These resources offer technical details on platform capabilities and integrations. Access them at the Cymulate resources page.

Implementation & Ease of Use

How easy is it to implement Cymulate and start using it?

Cymulate is designed for quick, agentless deployment with no additional hardware required. Customers can start running simulations almost immediately, with minimal resources and technical expertise. The platform is praised for its intuitive interface and ease of use. Source

What feedback have customers given about Cymulate’s ease of use?

Customers consistently praise Cymulate for its intuitive design and user-friendly dashboard. Testimonials highlight its simplicity, actionable insights, and effective support, making it accessible for both technical and non-technical users. Source

What support options are available for Cymulate customers?

Cymulate offers comprehensive support, including email support ([email protected]), real-time chat, a knowledge base, webinars, and e-books. These resources ensure a smooth onboarding and ongoing user experience. Webinars

Use Cases & Business Impact

Who can benefit from using Cymulate?

Cymulate is designed for CISOs, Security Operations teams, Red Teams, Detection Engineers, and Vulnerability Management teams across industries such as finance, healthcare, retail, and technology. The platform addresses universal cybersecurity challenges and is suitable for organizations of all sizes. Source

What business impact can organizations expect from Cymulate?

Organizations using Cymulate report a 30% improvement in threat prevention, 52% reduction in critical exposures, 60% increase in team efficiency, 40X faster threat validation, 85% improvement in detection accuracy, and up to 81% reduction in cyber risk within four months. Hertz Israel case study

What pain points does Cymulate address for security teams?

Cymulate addresses overwhelming threat volumes, lack of visibility, unclear prioritization, operational inefficiencies, fragmented tools, cloud complexity, and communication barriers for CISOs. It provides continuous threat validation, actionable insights, and unified metrics. Case studies

Are there industry-specific resources for financial services and healthcare?

Yes, Cymulate provides downloadable one-pagers summarizing solutions for financial services (Financial Services PDF) and healthcare (Healthcare PDF).

Security, Compliance & Certifications

What security and compliance certifications does Cymulate hold?

Cymulate is certified for SOC2 Type II, ISO 27001:2013, ISO 27701, ISO 27017, and CSA STAR Level 1. These certifications demonstrate adherence to industry-leading security and privacy standards. Source

How does Cymulate ensure data security and privacy?

Cymulate hosts services in secure AWS data centers, follows a strict Secure Development Lifecycle, enforces 2FA, RBAC, IP restrictions, and TLS encryption. The platform is GDPR-ready and supported by a dedicated privacy and security team. Source

Pricing & Plans

What is Cymulate’s pricing model?

Cymulate operates on a subscription-based pricing model tailored to each organization’s needs. Pricing depends on the selected package, number of assets, and testing scenarios. For a quote, schedule a demo.

Competition & Comparison

How does Cymulate compare to AttackIQ?

Cymulate offers a larger threat scenario library, AI-powered capabilities, and streamlined workflows, accelerating security posture improvement. AttackIQ does not match Cymulate’s innovation and threat coverage. Read more

How does Cymulate differ from Mandiant Security Validation?

Mandiant Security Validation is considered less innovative, while Cymulate continuously updates its platform with AI and automation, expanding into exposure management as a market leader. Read more

What advantages does Cymulate offer over Pentera?

Pentera focuses on attack path validation, while Cymulate provides deeper defense assessment, scales offensive testing, and increases exposure awareness with broader coverage. Read more

How does Cymulate compare to Picus Security?

Picus Security offers on-prem BAS, but Cymulate delivers a more complete exposure validation platform, covering the full kill chain and including cloud control validation. Read more

What makes Cymulate different from SafeBreach?

Cymulate features the industry’s largest attack library, a full CTEM solution, and comprehensive exposure validation, outpacing SafeBreach in innovation, precision, and automation. Read more

How does Cymulate compare to Scythe?

Scythe is suitable for advanced red teams building custom attack campaigns, while Cymulate is trusted by security teams focused on remediation and exposure elimination, offering actionable remediation and a user-friendly platform. Read more

Company, Vision & Resources

What is Cymulate’s mission and vision?

Cymulate’s mission is to empower organizations worldwide against threats and make advanced cybersecurity as simple as sending an email. The company aims to revolutionize cybersecurity by enabling proactive defense and effective security posture management. Source

How large is Cymulate and what is its market presence?

Founded in 2016, Cymulate serves over 1,000 customers in 50 countries and operates from eight global locations. Its continuous innovation and measurable outcomes demonstrate strong market viability. Source

Where can I find the latest Cymulate research and blog posts?

You can read the latest research, threat intelligence, and blog posts on the Cymulate blog. For research by Cymulate Research Lab, visit this page.

How can I subscribe to the Cymulate blog?

To subscribe to the Cymulate blog, you need to provide your full name, email address, and country of residence. Privacy Policy

Who authored the February 2021 wrap-up blog post and when was it last updated?

The blog post was authored by Cymulate and last updated on September 15, 2025. Author page

Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New: 2026 Gartner® Market Guide for Adversarial Exposure Validation
Learn More
New Research: Exploiting Configuration Trust in AI Coding Tools
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

Cymulate’s February 2021 Cyberattacks Wrap-up

By: Cymulate

Last Updated: September 15, 2025

cymulate

February 2021 remained active by threat actors, launching cyberattacks and new malware strains. We saw that organizations working on COVID-19 vaccines remained popular targets. During the month, threat actors attacked an Oxford University lab, which is researching and producing COVID-19 vaccines. They were able to gain access to its internal systems, including machines used to prepare biochemical samples.

Hospitals and Businesses Face Increasing Cyberattacks

In addition to Oxford University, due to the COVID-19 pandemic, overworked hospitals also remained prime targets for threat actors focusing on those that lack human and financial resources for IT and cybersecurity to replace outdated and obsolete software and hardware. During February, French hospitals were hit by a wave of cyberattacks that were conducted, according to the French minister for digital technology, by mafia-type organizations, often based in Eastern Europe. Other organizations such as French motorhome company Trigano and boat maker Beneteau also suffered cyberattacks in February 2021 harming its production.

Emergence of New Ransomware: Hades Locker

Threat actors keep fine-tuning their tools, launching new ransomware strains to optimize results. In February, ransomware Hades Locker was released. This new strain seems to be based on the Zyklon and Wildfire Lockers that were used in Kelihos botnet attacks last year. That botnet was also used in CryptFile2 and MarsJoke campaigns targeting state and local government agencies. With Hades Locker, the targets have shifted to manufacturing and business services verticals.

  • After distribution, the Hades Locker connected to http://ip-api.com/xml.
  • The IP address of the victim and its geographic location were collected.
  • A unique victim ID, a tracking ID, the computer name, the user name, the country, and the IP address of the victim were sent to the C&C server of the threat actors.
  • The C&C server replied with a password to encrypt the files using AES encryption.
  • The malware stored the unique victim ID and status entry in the registry.
  • Hades Locker then encrypted all files on mapped drives matching defined file extensions.
  • The malware executed the delete comment WMIC.exe shadowcopydelete/nointeractive to prevent file recovery by the victims.
  • Hades Locker created ransom notes containing links to the C&C servers.
  • The victim was instructed to access the Hades Locker payment site via two online C&C servers or via a specific TOR address.
  • Ransom payment had to be made in bitcoin to Hades Enterprises.

The Re-Emergence of DanaBot

Hades Locker was not the only malware making a comeback in February, DanaBot also re-emerged using a distribution method that tricks users into downloading malicious software disguised as VPNs, anti-virus programs, or online games. DanaBot hides two stealer components within the software key of pirated tools. The first software key was used to collect browser details, system information, and cryptocurrency wallets from the victim, while the second was used to install a cryptocurrency miner. In the past, DanaBot was used in targeted attacks on financial institutions predominantly located in the United States, Canada, Germany, United Kingdom, Australia, Italy, Poland, Mexico, and Ukraine. After disappearing in June last year, it reappeared at the end of 2020 and made its presence felt again in February 2021.

Introduction of Sophisticated Shellcode: BendyBear

In February, a new shellcode was detected. Dubbed BendyBear, It shares a lot of characteristics with the notorious WaterBear malware. The WaterBear malware family is associated with the cyberespionage group BlackTech, which has links to the Chinese government. The BendyBear shellcode loads directly into the memory of 64-bit computers and is capable of file transfer, shell access, screen capture, modified RC4 encryption, signature block verification, and polymorphic code while remaining obfuscated. The malware was used in recent attacks against several East Asian government organizations. What makes BendyBear a class on its own is its highly sophisticated, well-engineered (more than 10,000 bytes of machine code) and difficult-to-detect samples of shellcode employed during an Advanced Persistent Threat (APT).

Phishing Campaigns Employing Morse Code Obfuscation

In February, a new obfuscation technique was detected in a phishing campaign using Morse code to hide malicious URLs in an email attachment. The phishing campaign followed a familiar pattern:

  • An email was sent out pretending to contain an invoice.
  • It contained an HTML attachment spoofing as an Excel invoice.
  • The attachment included JavaScript that mapped letters and numbers to Morse code.
  • The script called a decodeMorse() function to decode a Morse code string into a hexadecimal string.
  • This hexadecimal string was decoded into JavaScript tags that were injected into the HTML page.
  • Once a user has entered their password, the form submitted that password to a remote site.
  • The threat actors collected the login credentials.

At least eleven companies were victimized, including SGS, Dimensional, Metrohm, SBI (Mauritius) Ltd, NUOVO IMAIE, Bridgestone, Cargeas, ODDO BHF Asset Management, Dea Capital, Equiniti, and Capital Four.

Mitigate Risks with Cymulate’s Immediate Threats Assessment

To find out if your organization is protected against the latest malware attacks, run Cymulate’s Immediate Threats assessment. This allows you to test and verify by yourself if your organization is exposed to these attacks. It also offers suggestions for mitigations in case it turns out that your organization is indeed vulnerable.

Also, IOCs are available at the Cymulate UI!

Stay cybersafe!

Cymulate Exposure Validation makes advanced security testing fast and easy. When it comes to building custom attack chains, it's all right in front of you in one place.
Mike Humbert, Cybersecurity Engineer
DARLING INGREDIENTS INC.
Learn More
GET A PERSONALIZED DEMO

Ready to see Cymulate in action?