Lilith is a malware name used for at least two distinct Windows threats in public reporting: an open-source remote administration tool and a separate ransomware family. The remote administration tool variant is a lightweight console-based C++ RAT for Windows that supports remote command execution through command shells and PowerShell, multiple client management, broadcast tasking, keylogging, startup persistence, and self-removal. Its modular design also allows operators to extend functionality with additional utilities and scripts. These capabilities make it suitable for unauthorized remote access and post-compromise control. Lilith has also been observed as a commodity RAT used by the SideCopy threat actor alongside other remote access tools in campaigns targeting government-related entities in India and Pakistan.
Separately, Lilith ransomware is a Windows 64-bit C/C++ console executable used for file encryption and extortion. It enumerates drives and files, excludes certain system-critical file types from encryption, terminates selected processes, interacts with the Windows Service Control Manager to stop services, encrypts victim files using Windows cryptographic APIs, renames encrypted files with a dedicated extension, and drops ransom notes threatening data leakage if payment negotiations do not begin within a short deadline. This behavior is consistent with modern double-extortion ransomware operations.
Because the same name is applied to materially different malware families, Lilith is an ambiguous designation rather than a single well-defined malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/tool listed as detectable via SHA-256 hash in a compilation of attacker infrastructure and malware-related indicators.
Ransomware that encrypts files, appends the .lilith extension, drops ransom notes named Restore_Your_Files.txt, terminates selected processes and services, enumerates drives and files, and threatens data leakage if payment is not made within three days.
A commodity remote access trojan used by SideCopy (observed since as early as 2019).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.