> Windows Syscalls
Back to malware index

Ransomware service-DLL swap pre-reboot (observed in LockBit variants)

Attributions are based on open-source threat reports. A family appearing here means at least one syscall record cites it; absence does not imply non-use.

1 syscalls cited