Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On 1 December 2023, Stairwell researchers acquired a copy of a server believed to be operated by the developers of the Kuiper ransomware... The Kuiper ransomware was first observed in September 2023, the same month they launched their own Ransomware-as-a-Service (RaaS).
"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Golang-based Kuiper ransomware is presented as an opportunity for other criminals to make money by ransoming one or more targets.
"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."
"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."
"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."
"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."
17 distinct techniques documented for this family, organized by ATT&CK tactic.
RobinHood stands out as a dual-role threat actor... operating the KUIPER RaaS program targeting Windows, Linux, ESXi, NAS, MacOS, and FreeBSD.
T1059.001 Command and Scripting Interpreter: PowerShell Example command: - Starts with “powershell.exe -ep bypass -w hidden -enc” followed by a space and the encoded command
T1059.003 Command and Scripting Interpreter: Windows Command Shell Example command: - Starts with “cmd.exe /c” followed by a space and the command to execute (i.e. “shutdown /r /t 8”)
The most common access type was RDP (Remote Desktop Protocol), appearing in 59 listings... By late 2023, VPN access listings had grown significantly, reflecting a shift in attack methodology.
T1489 Service Stop Example command: - “net stop” followed by the service name
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Golang-based cross-platform ransomware family targeting Windows, Linux, and macOS. It encrypts files, drops ransom notes, deletes backups and shadow copies, stops processes and services, attempts to disable Windows Defender, can reboot into safe mode, mount and encrypt shared drives, and spread laterally over SMB/WMIC.
A ransomware-as-a-service program advertised on RAMP, described as targeting Windows, Linux, ESXi, NAS, MacOS, and FreeBSD systems.
Golang-based ransomware operated as a Ransomware-as-a-Service. It encrypts files using RSA-4096 with AES-CFB and/or ChaCha20, drops ransom notes, appends the .kuiper extension, deletes Windows backups, kills administrative/analysis processes, and includes partially developed SMB/WMI-based self-propagation across local /24 subnets.
Ransomware/ESXi encryptor referenced as being supported or sold by ransomware actors targeting ESXi hypervisors for mass encryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.