AtomSilo is a Windows ransomware family first observed in 2021 that conducts file encryption and has been associated with double-extortion operations in which victim data is stolen and threatened with public release. It has been linked to intrusions where attackers gained access by exploiting Atlassian Confluence, established a foothold with a backdoor delivered through DLL side-loading, used WMI and compromised administrative accounts for remote command execution, and then deployed the ransomware payload.
AtomSilo is a 64-bit Windows executable, with reported samples packed using a modified UPX packer. It enumerates local drives, recursively traverses directories, and drops ransom notes in affected folders while excluding selected system directories, filenames, and extensions to preserve system stability. Encrypted files are renamed with an AtomSilo-specific extension. Analyses describe two closely related encryption implementations attributed to AtomSilo: one using a hybrid RSA-and-AES design with per-file AES keys protected with RSA, and another using partial file encryption with XOR and AES in repeating chunks, with encrypted key material and related metadata appended to the end of files. The malware uses memory-mapped file access during encryption and includes logic to avoid multiple concurrent instances.
The operation is notable for extortion messaging that threatens publication of stolen data on a leak site and demands large Bitcoin payments, sometimes with time-limited discounts. AtomSilo has been discussed alongside other ransomware families for which public decryptors were later released, and free decryption support has been made available for some AtomSilo victims. Reporting also notes later renewed activity by the AtomSilo operation in 2026.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since around 2021, HUI Loader variants have been deployed in operations involving the ransomware families LockFile, AtomSilo, NightSky, LockBit 2.0, and Pandora.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Since the victim’s public key is required to decrypt files later, AtomSilo clears it out in memory after encrypting and storing the result to avoid the key being recovered from memory.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation that has resumed activity and is disclosing new victims.
Ransomware that encrypts files, appends the .atomsilo extension, drops ransom notes, and is used in double-extortion attacks involving data exfiltration and publication on a leak site.
AtomSilo is a ransomware family associated in the report with HUI Loader-enabled operations and BRONZE STARLIGHT-linked activity.
Referenced only as another ransomware family for which Avast released a decryptor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.