AtomSilo is a Windows ransomware family that emerged around September 2021. Its operators use double extortion, encrypting victims’ files and threatening to publish stolen data. The ransomware is a 64-bit executable, with analyzed samples packed using a modified UPX packer. It enumerates drives, recursively traverses directories, and excludes selected system directories, filenames, and executable-related file types. It uses AES for file encryption and RSA to protect associated key material, storing encrypted key information with affected files. Analyzed variants perform partial file encryption through memory mapping. The payload uses a mutex to prevent simultaneous instances and places ransom notes in affected directories.
Observed AtomSilo intrusions began with exploitation of vulnerable Atlassian Confluence servers. Operators subsequently installed a backdoor through DLL side-loading and used compromised administrative accounts and WMI to execute Windows commands before deploying the ransomware. Microsoft identified AtomSilo among the ransomware families previously deployed by the China-based operator DEV-0401. HUI Loader variants have also appeared in operations involving AtomSilo. Victims have included a Brazilian pharmaceutical company whose stolen data was published by the operators. Avast released a free AtomSilo decryptor in October 2021.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DEV-0401 has previously deployed multiple ransomware families including LockFile, AtomSilo, and Rook.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Since the victim’s public key is required to decrypt files later, AtomSilo clears it out in memory after encrypting and storing the result to avoid the key being recovered from memory.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation that has resumed activity and is disclosing new victims.
Ransomware that encrypts files, appends the .atomsilo extension, drops ransom notes, and is used in double-extortion attacks involving data exfiltration and publication on a leak site.
AtomSilo is a ransomware family associated in the report with HUI Loader-enabled operations and BRONZE STARLIGHT-linked activity.
Referenced only as another ransomware family for which Avast released a decryptor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.