TellYouThePass is a financially motivated ransomware group operating the ransomware family of the same name, first observed in March 2019. Its operations target vulnerable internet-exposed systems, including Windows and Linux servers and organizations using financial management software in China. The group exploits newly disclosed vulnerabilities and weaknesses in unpatched enterprise applications to deploy ransomware and demand cryptocurrency payments for decryption. Its exploitation history includes EternalBlue-related vulnerabilities and flaws in WebLogic, Log4j, Apache ActiveMQ, office-automation platforms, financial management applications, and Hikvision products. In October 2023, it exploited Apache ActiveMQ vulnerability CVE-2023-46604 to deploy ransomware on Windows and Linux systems. A March 2024 campaign compromised thousands of computers running financial management services through command-execution vulnerabilities, encrypting local databases and documents. Beginning June 8, 2024, TellYouThePass exploited CVE-2024-4577, an argument-injection vulnerability enabling remote code execution in Windows PHP CGI deployments. These attacks used public exploit code to install web shells and deploy ransomware. The execution chain abused the Windows HTML Application host to run VBScript that decoded and loaded a .NET ransomware payload into memory. The malware disguised command-and-control communication as an HTTP request for a CSS resource. Its ransomware encrypts victim files and leaves payment instructions; documented campaigns demanded Bitcoin for decryption.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
其曾经使用过的代表性漏洞有:“永恒之蓝”系列漏洞、WebLogic应用漏洞、Log4j2漏洞、国内某OA系统漏洞、国内某财务管理系统漏洞等。
2023年10月,该病毒家族利用CVE-2023-46604漏洞发起攻击,在windows与 Linux 设备上利用 ActiveMQ 进行加密。
A critical remote code execution vulnerability in PHP CGI affects Windows versions of PHP CGI and allows unauthenticated attackers to execute arbitrary code remotely through argument injection. TellYouThePass began exploiting it after patches were released.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used CVE-2023-46604 in Apache ActiveMQ as a zero-day flaw in attacks.
Conducted ransomware activity targeting Apache ActiveMQ by exploiting CVE-2023-46604 as a zero-day.
Referenced as a threat group previously exploiting CVE-2023-46604 in Apache ActiveMQ to spread ransomware and other malware.
A ransomware group active since 2019, exploiting CVE-2024-4577 in Windows-based PHP running in CGI mode to deliver web shells and deploy ransomware. The content also associates TellYouThePass ransomware with earlier Log4Shell exploitation targeting Windows and Linux systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.