VHD is a Windows ransomware family first observed in March 2020 and associated with the North Korean Lazarus Group. It was used in targeted extortion operations against corporate networks, including an incident in Europe. Its deployment alongside the Lazarus-linked MATA framework connects it to the group's financially motivated activity.
Written in C++, VHD traverses connected disks and encrypts files using AES-256 in ECB mode combined with RSA-2048. It terminates processes that could lock files, including Microsoft Exchange and SQL Server processes, and deletes system volume information folders to impede recovery. It supports resuming interrupted encryption. For files larger than 16 MB, it stores intermediate cryptographic material on disk in plaintext without securely deleting it, potentially permitting partial recovery. Its use of ECB mode also preserves patterns in encrypted data.
VHD has been deployed with a separate, victim-tailored spreading utility that attempts SMB authentication using embedded administrative credentials, copies the ransomware through mounted network shares, and executes it remotely through WMI. Another observed operation involved exploitation of a vulnerable VPN gateway, privilege escalation, MATA deployment, and takeover of Active Directory before network-wide ransomware deployment. VHD was staged through a Python downloader, and the observed intrusion-to-deployment sequence took approximately ten hours.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2020, the group tried its hand at the big extortion game with the VHD ransomware family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware sample from a DPRK ransomware-family investigation, compared against BEAF for code and audio-profile similarities and differences.
Ransomware referenced as part of Lazarus’ broader toolset; no further technical detail provided in this content.
Ransomware written in C++ that encrypts files across connected disks, deletes restore-point related folders, stops processes such as Microsoft Exchange and SQL Server, and uses AES-256 in ECB mode with RSA-2048. It also supports resuming interrupted encryption and in some cases stores cryptographic material on disk in clear text.
Ransomware family used by Lazarus in extortion activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.