Milkyway Ransomware is a developing Windows-targeting ransomware strain reported by CYFIRMA (identified via underground forum monitoring) that targets organizational environments. It encrypts accessible files across infected systems, appends the ".milkyway" extension to encrypted data (e.g., "2.png" -> "2.png.milkyway"), and then displays a full-screen ransom message.
Per CYFIRMA’s reporting, the ransom note claims the victim’s servers, workstations, and backups are encrypted and unavailable, and uses coercive pressure tactics including threats to leak allegedly stolen data, report the victim to tax authorities/security services/law enforcement, share credentials/internal information, and contact the victim’s clients and partners. Victims are instructed to communicate with the attackers via a provided Outlook email address.
CYFIRMA maps Milkyway activity to multiple MITRE ATT&CK techniques and describes persistence and recovery-inhibition behaviors, including creating/modifying Windows scheduled tasks configured to run with SYSTEM-level privileges on recurring triggers (e.g., hourly or logon events), and deleting Volume Shadow Copies using commands such as "vssadmin.exe Delete Shadows /all /quiet" and "wmic shadowcopy delete /nointeractive." CYFIRMA assesses Milkyway is in an early/developing state and could evolve into a more sophisticated operation, potentially including a ransomware-as-a-service (RaaS) model.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The ransomware maintains long-term presence on the system by creating and modifying Windows scheduled tasks... set tasks to run with SYSTEM-level privileges... hourly or logon events.
The following are the TTPs based on the MITRE Attack Framework ... Execution T1059 Command and Scripting Interpreter
TTPs based on MITRE ATT&CK Framework ... Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell
...exposes native Windows API functions, such as OpenProcess, VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread.
The ransomware maintains long-term presence on the system by creating and modifying Windows scheduled tasks... set tasks to run with SYSTEM-level privileges... hourly or logon events.
Persistence T1112 Modify Registry; Defense Evasion T1112 Modify Registry
The ransomware maintains long-term presence on the system by creating and modifying Windows scheduled tasks... set tasks to run with SYSTEM-level privileges... hourly or logon events.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Encrypts accessible files on Windows systems, appends the ".milkyway" extension, displays a full-screen ransom message, and attempts to inhibit recovery by deleting Volume Shadow Copies (e.g., via vssadmin/wmic). Uses persistence mechanisms such as scheduled tasks and registry modifications; includes anti-analysis/anti-debug checks.
Windows-targeting ransomware that encrypts files (adding the .milkyway extension), displays a full-screen ransom note, and attempts to inhibit recovery by deleting Volume Shadow Copies (e.g., via vssadmin/wmic).
Windows-targeting ransomware that encrypts files (appending .milkyway) and presents a full-screen ransom note; attempts to inhibit recovery by deleting Volume Shadow Copies and uses persistence mechanisms (e.g., scheduled tasks/registry modifications).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.