Description Summary
Ransomware written in .NET, apparently derived from the codebase of win.hakbit (Thanos) ransomware.
Threat Actor
Built on the Thanos (win.hakbit) RaaS builder; publicly (and unverifiably) claimed a REvil affiliation.
Technical Indicators
Encryption Extension
.[random]
Encryption Algorithm
AES (Thanos/Hakbit builder)
Ransom Note Name
RESTORE_FILES_INFO.txt
Targeted Industries
Manufacturing, Financial, Government
First Seen
February 2021
Last Seen
2021
Geographical Location
Worldwide
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| Exfiltration x 1 | T1567 | Exfiltration Over Web Service (leak site) |
| Initial Access x 2 | T1190 | Exploit Public-Facing Application |
| T1078 | Valid Accounts |