Matrix is a Windows ransomware family first publicly identified in late 2016. It has primarily targeted small- to medium-sized organizations in multiple countries and is associated with both earlier opportunistic distribution and later hands-on intrusions. Early delivery was observed through spam campaigns, malicious shortcut files, and the RIG exploit kit, while later activity shifted toward brute forcing weak Remote Desktop Protocol credentials and abusing exposed remote access services to gain entry.
Once executed, Matrix encrypts files on local systems and accessible network shares, inhibits recovery by deleting volume shadow copies and disabling recovery options, and presents a ransom demand that commonly requires direct contact with the operators. A notable characteristic of Matrix is its variable ransom negotiation model: victims may be asked to submit several files for decryption so the operators can assess the victim and set a tailored payment demand. Matrix has also been associated with targeted deployment patterns rather than indiscriminate self-propagation inside victim environments.
Observed tradecraft mapped to Matrix includes use of valid accounts and brute-force access against remote services, command-shell execution, defense evasion through disabling or modifying security and recovery mechanisms, and impact through data encryption and system recovery inhibition. A Fox-branded variant is also associated with the Matrix family. Matrix is part of the broader evolution of ransomware from commodity spam-delivered malware toward manually operated intrusions against enterprise networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The below courses of action mitigate the following techniques: Spearphishing Attachment [T1566.001], Valid Accounts [T1078], Replication Through Removable Media [T1091], Remote Desktop Protocol [T1021.001]
The below courses of action mitigate the following techniques: Windows Command Shell [T1059.003], Match Legitimate Name or Location [T1036.005], Services File Permissions Weakness [T1574.010], Disable or Modify Tools [T1562.001], Service Stop [T1489], Modify Registry [T1112], Data Encrypted for Impact [T1486], Inhibit System Recovery [T1490]
The below courses of action mitigate the following techniques: Spearphishing Attachment [T1566.001], Valid Accounts [T1078], Replication Through Removable Media [T1091], Remote Desktop Protocol [T1021.001]
The below courses of action mitigate the following techniques: Windows Command Shell [T1059.003], Match Legitimate Name or Location [T1036.005], Services File Permissions Weakness [T1574.010]...
Encrypt large number of systems (and backups) using ransomware
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unsophisticated ransomware that gains access through vulnerable remote desktop services.
Matrix is a DDoS botnet campaign that leverages publicly available tools and exploits vulnerabilities in IoT devices, routers, telecom equipment, and enterprise systems to build a large-scale botnet capable of launching significant DDoS attacks. The campaign is notable for its use of open-source tools, integration of Mirai variants, and automated DDoS service sales via Telegram.
Ransomware family that encrypts files and network shares, deletes shadow copies, disables recovery options, and demands Bitcoin payment. It evolved from spam, malicious shortcuts, and RIG exploit kit distribution to primarily brute-forcing weak RDP credentials for targeted attacks against smaller organizations.
Ransomware family used in one of the domestic targeted ransomware cases.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.