TellYouThePass is a ransomware family active since 2019 that targets Windows and Linux systems. Its operators compromise internet-exposed servers through remote code execution and command-execution vulnerabilities, often exploiting newly disclosed flaws before organizations deploy patches. Campaigns have exploited Log4Shell, Apache ActiveMQ CVE-2023-46604, PHP-CGI CVE-2024-4577, and vulnerabilities in financial management software. Targets include enterprise servers, websites, and computers running financial management services, with large-scale campaigns affecting financial software users in China.
TellYouThePass encrypts documents, databases, and other files, changes their extensions, and creates ransom notes demanding cryptocurrency payments for decryption. Observed variants terminate application processes and stop database services to facilitate encryption. Windows variants attempt to delete Volume Shadow Copy snapshots to inhibit recovery. Implementations include Go-based payloads and a .NET variant. A Linux variant includes an SSH brute-force function. The ransomware also transmits victim-identifying information, including usernames, hostnames, and IP addresses, to attacker infrastructure; encryption can proceed even when this communication fails.
In campaigns exploiting CVE-2024-4577, attackers execute malicious HTML applications through the Windows HTML Application Host. Embedded VBScript decodes and loads a .NET ransomware payload into memory, while command-and-control traffic masquerades as requests for a CSS resource. These campaigns have also deployed web shells before executing the encryptor. The associated criminal operation is commonly tracked under the TellYouThePass name.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
其曾经使用过的代表性漏洞有:“永恒之蓝”系列漏洞、WebLogic应用漏洞、Log4j2漏洞、国内某OA系统漏洞、国内某财务管理系统漏洞等。
Arctic Wolf Labs has gathered forensic evidence showing that CVE-2023-46604 was being exploited in the wild as early as October 10, 2023, prior to the disclosure of a CVE or proof of concept exploitation code.
TellYouThePass ransomware was previously associated with Log4Shell exploitation, targeting Windows and Linux, and has been active since 2019. | The TellYouThePass ransomware gang has been leveraging CVE-2024-4577, a remote code execution vulnerability in PHP to deliver web shells and deploy ransomware on targeted systems.
The TellYouThePass ransomware gang has been leveraging CVE-2024-4577, a remote code execution vulnerability in PHP to deliver web shells and deploy ransomware on targeted systems.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
经360安全智脑的分析研判,成功锁定了这一波攻击的来源为TellYouThePass勒索家族——一家擅长利用服务器漏洞进行规模化攻击的老牌勒索软件家族。
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Chyba súvisí s konverziou kódovania znakov cez funkciu Windows Best-Fit a prostredníctvom injekcie príkazov ju možno zneužiť na vzdialené vykonanie kódu.
A cmd.exe process is spawned by java.exe out of the respective Apache ActiveMQ application folder.
The file contained a VBScript, which in turn resulted in the deployment of a .NET variant of TellYouThePass ransomware.
The vulnerability, tracked as CVE-2024-4577 (CVSS: 9.8), is a Remote Code Execution (RCE) vulnerability. Exploitation would allow a remote and unauthenticated threat actor to reveal the source code of scripts and run arbitrary code on vulnerable servers.
46 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used by the TellYouThePass gang; the content notes it targeted Apache ActiveMQ vulnerability CVE-2023-46604 as a zero-day.
Ransomware payload detected as part of Log4j exploit attempts.
Ransomware that encrypts files and demands payment, spread via exploitation of Apache ActiveMQ vulnerability.
Ransomware family mentioned as previously exploiting CVE-2023-46604 in Apache ActiveMQ.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.