{"id":59565,"date":"2025-10-23T00:00:00","date_gmt":"2025-10-23T00:00:00","guid":{"rendered":"urn:uuid:8fd84c77-fa74-eb3f-83a4-a186e5190685"},"modified":"2025-10-23T00:00:00","modified_gmt":"2025-10-23T00:00:00","slug":"agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\/","title":{"rendered":"Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/agenda-thumb:Large?qlt=80\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/25\/agenda-thumb.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Analysis of the embedded obfuscated JavaScript within these &nbsp;fake CAPTCHA pages revealed a multistage payload delivery system that initiated downloads from secondary command-and-control servers:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">45[.]221[.]64[.]245\/mot\/<\/span><\/li>\n<li><span class=\"rte-red-bullet\">104[.]164[.]55[.]7\/231\/means.d<\/span><\/li>\n<\/ul>\n<p>We assess that the threat actors likely initiated their attack campaign through a sophisticated social engineering scheme involving these &nbsp;fake CAPTCHA pages. The pages appear to have delivered information stealers to the compromised endpoints, which subsequently harvested authentication tokens, browser cookies, and stored credentials from the infected systems. The presence of valid credentials used throughout the attack chain strongly suggests that these stolen credentials provided the Agenda threat actors with the valid accounts necessary for their initial access into the environment. This assessment is further supported by the attackers\u2019 ability to bypass multifactor authentication (MFA) and move laterally using legitimate user sessions, indicating they possessed harvested credentials rather than relying on traditional exploitation techniques.<\/p>\n<p><b>Privilege Escalation<\/b><\/p>\n<p>The attackers deployed a SOCKS proxy DLL to facilitate remote access and command execution. This proxy was loaded directly into memory using Windows\u2019 legitimate rundll32.exe process, making detection more difficult.<\/p>\n<p>&nbsp;<i>|\u2500\u2500 C:\\Windows\\System32\\cmd.exe<\/i><\/p>\n<p><i>\u2514\u2500\u2500 C:\\Windows\\System32\\rundll32.exe<\/i><\/p>\n<p><i>\u2514\u2500\u2500 rundll32.exe socks64.dll,rundll<\/i><\/p>\n<p><i>\u2514\u2500\u2500 C:\\ProgramData\\Veeam\\socks64.dll<\/i><\/p>\n<p>A backdoor administrative account named \u201c<i>Supportt<\/i>\u201d was created to ensure persistent elevated access. This account name was likely chosen to blend in with legitimate support accounts commonly found in enterprise environments.<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><i>net user Supportt ***** \/add<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>net localgroup Administrators Supportt \/add<\/i><\/span><\/li>\n<\/ul>\n<p>The legitimate administrator account password was also reset to maintain control and prevent legitimate administrators from regaining access.<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><i>net user Administrator *****<\/i><\/span><\/li>\n<\/ul>\n<p><b>Discovery<\/b><\/p>\n<p>Extensive reconnaissance was conducted to map the network infrastructure. The attackers abused ScreenConnect\u2019s legitimate remote management capabilities to execute discovery commands through temporary command scripts, systematically enumerating domain trusts and identifying privileged accounts while appearing as normal administrative activity:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">nltest \/domain_trusts<\/span><\/li>\n<li><span class=\"rte-red-bullet\">net group &#8220;domain admins&#8221; \/domain<\/span><\/li>\n<\/ul>\n<p>Network scanning tools were deployed across multiple locations to discover additional systems, services, and potential lateral movement targets. The NetScan utility was executed from both the Desktop and Documents folders to perform comprehensive network enumeration.<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">C:\\Users\\Administrator.&lt;REDACTED&gt;\\Desktop\\netscan.exe<\/span><\/li>\n<li><span class=\"rte-red-bullet\">C:\\Users\\Administrator.&lt;REDACTED&gt;\\Documents\\netscan.exe<\/span><\/li>\n<\/ul>\n<p>Remote management tools were strategically installed through legitimate RMM platforms to blend with normal IT operations. ATERA Networks\u2019 agent was leveraged to deploy AnyDesk version 9.0.5, while ScreenConnect provided an additional command execution vector. This dual-RMM approach provided the attackers with redundant remote access capabilities that appeared legitimate to security monitoring systems, allowing them to maintain persistent access even if one tool was discovered and removed.<\/p>\n<p><b>Credential Access<\/b><\/p>\n<p>The attackers specifically targeted Veeam backup infrastructure to harvest credentials, recognizing that backup systems often store credentials for accessing multiple systems across the enterprise. PowerShell scripts were executed with base64-encoded payloads to extract and decrypt stored credentials from Veeam databases, via powershell.exe -e [base64-encoded payload].<\/p>\n<p>When decoded, these scripts revealed systematic targeting of multiple Veeam backup databases, each containing credentials for different segments of the infrastructure:<\/p>\n<p><b>SQL Database Queries:<\/b><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">SELECT [user_name], [password] FROM [VeeamBackup].[dbo].[Credentials]<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Targeted tables: Credentials, BackupRepositories, WinServe<\/span>rs<\/li>\n<\/ul>\n<p><b>Compromised Account Types:<\/b><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Domain administrator accounts: DOMAIN\\admin-***, DOMAIN\\da-backup-***<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Service accounts: svc-sql-***, DOMAIN\\veeam-svc-***, svc-exchange-***<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Local administrators: SERVER01\\Administrator, SERVER02\\localadmin<\/span><\/li>\n<\/ul>\n<p><b>Script Details:<\/b><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Decryption key found in script: 0jmz9Hrgy08rc0XrNpQ***[REDACTED]***<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Affected systems: Domain controllers, Exchange servers, SQL databases, file servers, backup repositories<\/span><\/li>\n<\/ul>\n<p>This approach provided the attackers with a comprehensive set of credentials for remote systems, domain controllers, and critical servers stored within the backup infrastructure.<\/p>\n<p><b>Defense Evasion<\/b><\/p>\n<p>The attackers deployed sophisticated anti-analysis tools to evade security solutions. Further probe confirmed that both 2stX.exe and Or2.exe utilize the eskle.sys driver for anti-AV capabilities through a BYOVD attack:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">C:\\Users\\Administrator.&lt;REDACTED&gt;\\Downloads\\2stX.exe<\/span><\/li>\n<li><span class=\"rte-red-bullet\">C:\\Users\\Administrator.&lt;REDACTED&gt;\\Downloads\\Or2.exe<\/span>\n<ul>\n<li><span class=\"rte-circle-bullet\"><\/span>C:\\Users\\Administrator.&lt;REDACTED&gt;\\Downloads\\2stX\\eskle.sys<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>The eskle.sys driver was utilized to disable security solutions, terminate processes, and evade detection.&nbsp;Although these files could have been downloaded or copied onto the machine earlier, the origin of the eskle.sys driver is unclear. Its digital signature lists the vendor as \u201c\u62c7\u6307\u4e16\u754c\uff08\u5317\u4eac\uff09\u7f51\u7edc\u79d1\u6280\u6709\u9650\u516c\u201c (translated: Thumb World (Beijing) Network Technology Co., Ltd.), which appears to be associated with the game.bb site. The driver likely belongs to a game-related package and is commonly used by cheat developers to evade anti-cheat systems; however, it could also be repurposed by advanced persistent threat actors.<\/p>\n<p> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/25\/j\/agenda-ransomware-deploys-linux-variant-on-windows-systems.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Trend\u2122 Research identified a sophisticated Agenda ransomware attack that deployed a Linux variant on Windows systems. This cross-platform execution can make detection challenging for enterprises. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":59566,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9534,9539,9509],"class_list":["post-59565","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-latest-news","tag-trend-micro-research-ransomware","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2025-10-23T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/agenda-thumb:Large?qlt=80\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques\",\"datePublished\":\"2025-10-23T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\\\/\"},\"wordCount\":755,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques.jpg\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Latest News\",\"Trend Micro Research : Ransomware\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\\\/\",\"name\":\"Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques.jpg\",\"datePublished\":\"2025-10-23T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques.jpg\",\"width\":976,\"height\":533},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\/","og_locale":"en_US","og_type":"article","og_title":"Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2025-10-23T00:00:00+00:00","og_image":[{"url":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/agenda-thumb:Large?qlt=80","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques","datePublished":"2025-10-23T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\/"},"wordCount":755,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/10\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques.jpg","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Latest News","Trend Micro Research : Ransomware","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\/","url":"https:\/\/www.threatshub.org\/blog\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\/","name":"Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/10\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques.jpg","datePublished":"2025-10-23T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/10\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/10\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques.jpg","width":976,"height":533},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/agenda-ransomware-deploys-linux-variant-on-windows-systems-through-remote-management-tools-and-byovd-techniques\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/59565","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=59565"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/59565\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/59566"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=59565"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=59565"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=59565"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}