Thanos is a .NET-based ransomware family and ransomware-as-a-service offering that emerged in late 2019 and was publicly identified in early 2020. Written in C#, it was marketed with a builder that allowed affiliates and other operators to generate customized variants, contributing to broad downstream reuse after the builder or source code leaked. Thanos became an important progenitor for several later ransomware operations and variants, including Prometheus, Haron, Spook, Midas, and AlumniLocker, although code overlap alone does not always prove common operators.
Thanos is designed for Windows environments and supports a wide range of enterprise-impacting behaviors beyond file encryption. Reported capabilities include process injection, anti-analysis checks, anti-sniffer and anti-termination protections, persistence through Startup-folder artifacts, service and process termination to unlock files and disable defenses, deletion of shadow copies and backups, and modification of firewall or system settings to facilitate execution and recovery inhibition. Some variants also implement network spreading or lateral movement features, including use of remote execution tooling against other Windows hosts. Thanos has been observed using RIPlace, a file-rename evasion technique intended to bypass some anti-ransomware and EDR protections, and using ProcessHide to hook system APIs and conceal its process from user-space monitoring tools.
Encryption behavior varies across variants and over time. Multiple reports describe Thanos using hybrid encryption schemes combining symmetric file encryption with asymmetric protection of keys, while some descendants use Salsa20-based routines. The family commonly drops ransom notes in text and HTA formats and has been associated with double-extortion operations in which operators claim to steal data before or during encryption and threaten public release if victims do not pay.
Thanos has been distributed through several intrusion paths. Observed delivery mechanisms include phishing emails with malicious attachments or lures, malicious document and script chains, PowerShell-based loaders, and deployment after prior compromise by access brokers or loaders. It has also been linked to affiliate ecosystems and underground forum advertising. In one notable state-linked context, Iranian actor MuddyWater was assessed to have attempted deployment of a destructive Thanos variant via the PowGoop loader, apparently to disrupt operations or destroy evidence rather than for straightforward financial extortion.
The family has affected organizations across multiple sectors and geographies through both criminal and suspected state-linked activity. Its leaked builder and flexible feature set made it a durable foundation for follow-on ransomware campaigns throughout 2021 and beyond.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MuddyWater has previously attempted to deploy ransomware, such as Thanos, on victim networks to either destroy evidence of their intrusions or disrupt operations.
Cyble researchers have found a sample of the Thanos ransomware being used by the Prometheus group for a recent ransomware attack.
"...overlap between targeted intrusion operations by STATIC KITTEN and disruption-oriented Thanos ransomware activity..."
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Может распространяться путём взлома через незащищенную конфигурацию RDP...
...обманных загрузок, ботнетов, эксплойтов, вредоносной рекламы, веб-инжектов, фальшивых обновлений, перепакованных и заражённых инсталляторов.
MITRE ATT&CK Technique ID Technique T1059 Command and Scripting Interpreter
ProcessHide then hooks the NtQuerySystemInformation API call to hide the process from being listed by the monitoring applications.
The ZIP archive also contains a fake JPG file, which is actually a PowerShell script that will download and execute the AlumniLocker payload by abusing a Background Intelligent Service Transfer (BITS) module.
Defense Evasion The below courses of action mitigate the following techniques: Disable or Modify Tools [T1562.001], Modify Registry [T1112]
Может распространяться путём взлома через незащищенную конфигурацию RDP...
Файл может называться: firefox.exe или chrome32.exe, opera32.exe, firefox.exe, server.exe, client.exe и пр.
The ZIP archive also contains a fake JPG file, which is actually a PowerShell script that will download and execute the AlumniLocker payload by abusing a Background Intelligent Service Transfer (BITS) module.
118 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in passing as a ransomware operation that has run an affiliate program.
Mentioned only in passing as a ransomware builder referenced from prior investigations.
Ransomware family with a leaked builder; presented as the upstream code lineage for Prometheus and a source of shared artifacts and behavior seen in Spook.
A named ransomware example listed in the RAMP malware marketplace.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.