Ransomware is malware that encrypts a victim organization's data and demands payment in exchange for restoration, often combining encryption with data theft and extortion through threats to leak stolen information. It is a broad malware category rather than a single family. Ransomware operations commonly target organizations across sectors and sizes, including healthcare, manufacturing, and other enterprises, where disruption of operations increases pressure to pay. Delivery frequently occurs through social engineering and other intrusion vectors, and operators may deploy ransomware directly onto compromised endpoints after initial access. Python-based ransomware variants have also been observed packaged with PyInstaller, including samples whose recovered components clearly indicate file-encryption functionality. In enterprise incidents, ransomware is often associated with broader post-compromise activity, delayed detection, and significant operational impact.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
USERNAME & PASSWORD COMPROMISE Attackers can use compromised usernames and passwords to log on to your workstation remotely, or gain acces to your agency’s network.
INFECTED USB DEVICES (USB Sticks, Thumbdrives, Smartphones, Etc) Ransomware can infect a computer when a user attaches an infected USB device. Attackers may leave thumbdrives in public places hoping you will insert them into your computer.
DRIVE-BY-DOWNLOAD Attackers will host ransomware on websites or through advertising networks. Just visiting a malicious site will enable malware or ransomware infection.
In addition, exploitation of vulnerabilities, phishing attacks, and attacks via malicious emails are primary attack vectors to infect victims with ransomware.
A service supply chain attack targets service providers, such as Managed Service Providers (MSPs), and uses their trusted access to deploy malware across multiple customer environments.
Since MSPs are entrusted with managing and operating client networks, attackers can use them as distribution points for malware like ransomware.
A cybercriminal used Claude to develop, market, and distribute several variants of ransomware, each with advanced evasion capabilities, encryption, and anti-recovery mechanisms.
Then he successfully deployed ransomware, right under the program's nose.
A ransomware attack on Colonial Pipeline’s business systems in 2021 led them to disconnect operational systems for five days and caused gas stations to run out of fuel in 13 states and Washington, DC, demonstrating the outsized effect of an attack on one critical energy company.
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware is malware that encrypts files on a device or network and demands payment for decryption.
A Python-based ransomware sample packaged as a 64-bit ELF executable with PyInstaller. The recovered source indicates ransomware behavior, including functions such as write_key(), and the sample is noted as possibly intended for Windows Subsystem for Linux (WSL).
Ransomware is used in cyberattacks to encrypt an organization's data with encryption algorithms and demand ransom for data recovery. Criminals may also steal confidential information and extort organizations with threats of data leaks.
Mentioned only in a sidebar link title; ZeusVM is referenced incidentally.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.