White Rabbit is a targeted ransomware family first publicly observed in late 2021 during an intrusion affecting a U.S. financial institution. It is notable for requiring a specific command-line password or passphrase to decrypt its internal configuration and activate its encryption routine, a design choice that can make the payload appear inert during superficial analysis and contributes to defense evasion. The malware has been described as using evasion tradecraft reminiscent of Egregor.
Once executed with the correct parameters, White Rabbit encrypts data across local fixed drives, removable media, network drives, and other reachable network resources, while excluding selected system-critical directories and file types to reduce the chance of rendering the host unusable. It creates ransom notes for encrypted files and has been associated with double-extortion operations in which victims are threatened with publication or sale of stolen data in addition to file encryption. Prior to encryption, it terminates multiple processes and services, particularly security-related software, to improve execution success.
Operational reporting has linked White Rabbit to highly targeted intrusions rather than broad opportunistic campaigns. A possible association with FIN8 has been reported based on overlapping intrusion telemetry, including Cobalt Strike activity and use of a Badhatch variant, but a direct authorship or operational relationship has not been conclusively established. White Rabbit has also been cited in reporting on collaboration among ransomware actors targeting financial services organizations. Assessments from early analysis suggested the malware's encryption workflow was comparatively simple and possibly still under development, but its targeted deployment and modern extortion model made it a credible enterprise threat.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We spotted the new ransomware family White Rabbit discretely making a name for itself by executing an attack on a local US bank in December 2021.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family mentioned as collaborating with other ransomware groups to target financial services firms.
A newly observed ransomware family that uses a command-line password to decrypt its internal configuration before executing, employs double extortion, terminates security-related processes and services, and encrypts files across fixed, removable, and network drives while skipping selected system paths.
Ransomware used/deployed by FIN8 (details not provided beyond deployment).
Ransomware referenced as deployed by FIN8.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.