RansomBoggs is a .NET ransomware family used in attacks against organizations in Ukraine and publicly linked to the Russia-aligned Sandworm threat group. It emerged in late 2022 during a broader wave of destructive and disruptive operations associated with Russia’s war against Ukraine, alongside multiple wipers and faux-ransomware families employed against government, energy, logistics, and other Ukrainian targets. Reporting places RansomBoggs within Sandworm’s pattern of using malware that can serve either overt extortion-themed disruption or destructive objectives in support of geopolitical operations.
RansomBoggs has been described as ransomware rather than a pure wiper, but its operational context strongly associates it with Sandworm’s wider disruptive campaigns. It was observed in Ukraine in November 2022, and the same deployment scripting used in related Sandworm operations was also used to distribute it. Sandworm has repeatedly relied on compromise of Active Directory environments and deployment through Group Policy, including use of POWERGAP scripts, to push destructive payloads and ransomware-like malware across victim networks. This indicates RansomBoggs was likely intended for enterprise-scale deployment after significant post-compromise access had already been achieved.
The malware is associated with attacks in a wartime targeting environment rather than conventional financially motivated cybercrime. It has been referenced alongside other Sandworm-linked malware such as CaddyWiper, HermeticWiper, IsaacWiper, Industroyer2, Prestige, WhisperGate, and ZeroWipe, underscoring its role in a sustained campaign of disruptive operations against Ukrainian entities. High-confidence public reporting ties waves of RansomBoggs attacks in Ukraine to Sandworm, a GRU-linked threat actor known for destructive attacks against critical infrastructure and other strategically significant sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Two months ago, ESET detected a wave of RansomBoggs ransomware attacks in the war-torn country that were also linked to Sandworm.
1 distinct technique documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in a list of wipers observed after AcidRain.
Destructive wiper (despite the name) listed among wipers used in 2022 attacks.
Wiper malware referenced as used in 2022 attacks aimed at Ukraine.
Malware referenced as used in 2022 attacks targeting Ukraine; despite the name, it is listed in the content among wipers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.