Description Summary
Abyss Locker emerged in March 2023 as a ransomware-as-a-service with both Windows and Linux/ESXi encryptors. It is assessed to be derived from the leaked HelloKitty source code. Abyss focuses on virtualized infrastructure, particularly VMware ESXi servers, for maximum business impact.
Threat Actor
Closed RaaS operators; HelloKitty code lineage.
Technical Indicators
Encryption Extension
.crypt
Encryption Algorithm
ChaCha20 + Curve25519 (HelloKitty-derived)
Ransom Note Name
WhatHappened.txt
Targeted Industries
Manufacturing, Technology, Financial, Hospitality
First Seen
March 2023
Last Seen
Active
Geographical Location
Global
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| Execution x 1 | T1059 | Command and Scripting Interpreter |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 2 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 2 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| Impact x 3 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop |