FIVEHANDS is a Windows ransomware family related to DeathRansom and HelloKitty, associated with the financially motivated threat cluster UNC2447. It has been deployed against organizations in North America and Europe following exploitation of CVE-2021-20016 in SonicWall SMA 100 Series VPN appliances, including activity before patches became available in February 2021. FIVEHANDS intrusions have also involved the SombRAT remote access trojan and legitimate reconnaissance and remote-administration tools.
FIVEHANDS encrypts victim files using the NTRUEncrypt public-key encryption scheme with an embedded public key and places ransom notes in affected directories. It enumerates network shares and mounted drives, supports command-line arguments that restrict encryption to specified directories, and avoids encrypting key system files. To inhibit recovery, it uses Windows Management Instrumentation to enumerate and delete Volume Shadow Copies and also encrypts files associated with system recovery. Its loader decrypts an embedded ransomware payload in memory using an operator-supplied key, validates the decoded executable, and executes it. Operators have used PsExec to distribute and launch the ransomware remotely with system privileges.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023).
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023).
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023).
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat.
One of the most prolific and successful Conti affiliates—and the one responsible for developing the “Conti Manual” leaked in August 2021—is tracked as DEV-0230. This activity group also developed and deployed the FiveHands and HelloKitty ransomware payloads...
14 distinct techniques documented for this family, organized by ATT&CK tactic.
it uses Windows Management Instrumentation (WMI) to enumerate Volume Shadow copies using the command “ select * from Win32_ShadowCopy” and then deletes copies by ID (Win32_ShadowCopy.ID).
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
In these cases, the threat actors were able to delete cloud-stored backups prior to ransomware deployment.
Vice Society is known for its extortion tactics, encrypting devices and demanding a ransom.
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
42 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group/family referenced in connection with access to logistics-sector victims, likely leveraging SonicWall-related access for ransomware attacks.
Ransomware capable of deleting volume shadow copies on compromised hosts.
Ransomware that can enumerate network shares and mounted drives on a network.
Ransomware mentioned only in a cited report title associating it with UNC2447 and SOMBRAT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.