Industrial Spy is a Windows ransomware family associated with a corporate-data theft and extortion operation. Its file-encrypting ransomware was first observed in the wild in May 2022. The operation initially ran a marketplace selling stolen corporate information before adding ransomware to support double extortion, combining file encryption with threats to disclose stolen data. It has also conducted data-extortion operations without encryption.
The ransomware encrypts up to the first 100 MB of each targeted file using Triple DES, protecting each file’s encryption key and initialization vector with an embedded RSA public key. It leaves file extensions unchanged and appends metadata identifying encrypted files. It can recursively encrypt specified paths or enumerate writable volumes, using separate encryption threads. It deletes Windows Volume Shadow Copies to hinder recovery, attempts to terminate processes locking targeted files through the Windows Restart Manager API, places ransom notes in affected directories, and deletes itself after execution. It uses limited stack-string obfuscation and excludes selected application directories and executable-related file types.
A separate, non-encrypting promotional component advertised the stolen-data marketplace through text notices and desktop wallpaper changes. This component was distributed through malware downloaders disguised as software cracks and adware; that distribution should be distinguished from delivery of the ransomware itself.
Industrial Spy has been deployed by the Russia-based threat actor Storm-0978, also known as RomCom, in financially motivated attacks, including a documented healthcare intrusion. Its configuration shares similarities with Cuba ransomware. Underground ransomware is a closely related successor with substantial code overlap.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The threat actors deployed Industrial Spy ransomware, which shares distinct similarities in configuration to Cuba ransomware.
The threat actors deployed Industrial Spy ransomware, which shares distinct similarities in configuration to Cuba ransomware.
The hackers also use Industrial Spy ransomware during financially motivated attacks. This ransomware was first discovered in the wild in May 2022.
After March 2022, attacks using Cuba ransomware were entirely replaced by Industrial Spy, which appears to be a continuation of the former.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware payload used in RomCom-linked double-extortion operations (encrypting data and threatening leaks).
Ransomware used by the group as part of its evolving ransomware toolkit.
Ransomware used by Nebulous Mantis after March 2022, described as a continuation/replacement of Cuba ransomware, deployed to encrypt victim data and demand ransom (coverage for prior data theft).
Named ransomware family mentioned only for its close relationship to Underground. No deployment, technical behavior, or involvement in the analyzed campaign is described.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.