DeathRansom is a Windows ransomware family first observed in November 2019, with early distribution documented in South Korea. It processes files on local and network drives and demands Bitcoin payment for decryption. Initial variants merely renamed files without encrypting their contents, allowing recovery by reversing the filename changes. Later variants implemented genuine encryption and generally left file extensions unchanged.
DeathRansom recursively enumerates directories, logical drives, and network resources using Windows APIs. It excludes selected system directories and files from processing and places ransom notes in affected directories. An analyzed encryption implementation combines Curve25519-based ECDH, Salsa20, RSA-2048, and an AES-256-based XOR keystream. It generates per-file symmetric keys, protects them with RSA, and appends encrypted key material and a marker to affected files. Some implementations encrypt only an initial portion of each file. Victim-specific cryptographic material is stored in the Windows registry, and ransom notes provide a unique identifier for communication with the operators.
Some versions check operating-system language and keyboard settings and terminate when they detect Russian, Kazakh, Belarusian, Ukrainian, or Tatar. DeathRansom can also use Windows Management Instrumentation to delete Volume Shadow Copies, hindering recovery. Packed samples use staged in-memory unpacking and dynamic API resolution. HelloKitty is a related ransomware family, and FiveHands is a later rewrite of DeathRansom observed in extortion incidents in early 2021; their campaign-specific behavior should not be assumed to apply to the original DeathRansom family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FortiGuard Labs recently discovered an ongoing DeathRansom malicious campaign... as you may remember from our first blog, DeathRansom uses the name ‘Wacatac’ to store crypto keys in a registry.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Examples include: "Babuk can enumerate disk volumes," "Confucius has used a file stealer that can examine system drives," and "XAgentOSX contains the getInstalledAPP function to run ls -la /Applications to gather what applications are installed."
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
APT1 listed connected network shares. APT32 used the net view command to show all shares available, including the administrative shares such as C$ and ADMIN$. APT41 used the net share command as part of network reconnaissance.
DeathRansom performs a check for the system language, and it will not encrypt files if it detects locales from an ex-USSR country.
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware that deletes volume shadow copies on compromised hosts.
Ransomware with at least two described variants: one variant merely appends the ".wctc" extension without actually encrypting file contents, while another encrypts files without appending an extension. The sample discussed is packed and uses staged shellcode unpacking via APIs such as LocalAlloc, VirtualAlloc, VirtualProtect, and GetProcAddress before revealing the final PE payload.
Ransomware capable of enumerating network resources via loop operations.
Encrypts files using public/private-key cryptography to demand ransom payment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.