EKANS, also known as Snakehose and sometimes mislabeled as Snake, is a Windows ransomware family publicly disclosed in early 2020 and notable for incorporating industrial-control-system-aware process termination logic. It is written in Go and has been used in targeted attacks against high-profile organizations, including manufacturing and other industrial-sector victims. Security reporting has associated EKANS activity with attempted or actual disruptions affecting organizations in electric, oil and gas, medical, pharmaceutical manufacturing, and automotive environments.
The malware is designed primarily for monetization rather than espionage or destructive state activity. Available evidence does not support a provable connection between EKANS and the Turla espionage platform also known as Snake. EKANS is better understood as criminal ransomware that can nevertheless create serious operational consequences in industrial environments because it forcibly stops selected processes before encrypting systems. Its built-in kill list includes security, management, and OT-relevant Windows processes, including software associated with ICS operations, data historians, and licensing services. This behavior is assessed primarily as a means to remove file locks and maximize encryption coverage, but in practice it can interrupt production and other operational workflows.
Observed functionality includes process termination, host domain discovery, use of Windows Management Instrumentation for execution-related operations, deletion of Volume Shadow Copies to inhibit recovery, and masquerading under benign-looking executable names. EKANS also uses a mutex to avoid reinfecting the same host. Multiple analyses have noted similarities or relationships between its process-kill logic and earlier ransomware activity involving MegaCortex and possibly LockerGoga. EKANS is widely cited as one of the ransomware families that helped demonstrate the growing convergence of financially motivated ransomware operations with OT-aware tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Akira has used legitimate names and locations for files to evade defenses.
一般的なランサムウェアは一ファイルずつファイルを暗号化→拡張子変更の流れをとるのではなく、全てのファイルに対する暗号化を一通り実施した後に、最後にまとめてファイルの拡張子だけを変更していきます。...挙動検知などに対する検知逃れの効果などが考えられます。
SNAKE first encrypts all files (without changing file extensions). Once all encryptions are done, it changes all file extensions at a time.
In that case, they had access to the domain administrator’s account, compromised in the attack’s earlier stages.
If the function that checks the attacked computer’s domain role returns “1” (i.e., the computer has the role of a primary or backup domain controller), the function that calls it returns “0”. This results in the malware terminating without performing any encryption.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
A unique feature of this specimen is that it specially works when the work environment is a domain controller... First, SNAKE uses WMI queries to refer the domain role value.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
If the function that checks the attacked computer’s domain role returns “1” (i.e., the computer has the role of a primary or backup domain controller), the function that calls it returns “0”. This results in the malware terminating without performing any encryption.
After the environment settings are ready, encryption of the files that is the main process of the ransomware begins. File encryption takes all drives available in the system and encrypts them in order from the beginning of the drive.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware that removes Volume Shadow Copy backups to disable restoration.
Referenced as ransomware known to target OT-related Windows processes.
Ransomware family mentioned as one of several strains deployed alongside process kill lists intended to amplify ransomware effects.
Determines the domain of compromised hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.