Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Monkey Ransomware, which appends a ‘.monkey’ extension to encrypted files, has appeared in multiple variants written in different programming languages since its debut in late 2025.”
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Версия Monkey Ransomware на C++ закрепляется через планировщик задач; Golang-вариант закрепляется через crontab.
The C++ Monkey variant “can establish persistence via a scheduled task.”
Monkey ransomware variants encrypt victim files using ChaCha20-Poly1305, AES-256-CBC, and other implementations.
“The malware also takes steps to terminate unnecessary processes” before encryption.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family that encrypts files and appends the .monkey extension. It has rapidly evolved through multiple programming-language variants; the report speculates this iteration may be accelerated by generative-AI-assisted development. Hacking Cat disputed attribution for the ransomware variants.
Ransomware that encrypts user data and appends the .monkey extension. Numerous variants were observed, including versions written in different programming languages.
A multi-platform ransomware family attributed with high confidence to Hacking Cat. Windows variants use ChaCha20-Poly1305 or AES-256-CBC, while the Golang variant targets Linux and ESXi. It impairs recovery and defenses, terminates processes and services, escalates privileges, establishes persistence, and may steal Outlook credentials. Some Rust variants do not retain encryption keys, making them operationally equivalent to destructive wipers despite leaving ransom notes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.