Spora is a Windows ransomware family first observed in early 2017 and notable for combining file encryption with worm-like propagation techniques. It can encrypt victim files without requiring immediate network communication, and it checks for an infection marker derived from the system’s volume information to determine whether it is already running. This behavior enabled the development of defensive vaccination-style mitigations that pre-create the expected marker.
Spora was distributed through multiple delivery channels, including malicious spam and exploit-kit activity associated with the EITest campaign. In those campaigns it was also delivered through fake browser update or font-update lures targeting Chrome users. The malware was regarded as one of the more prevalent ransomware families of its period.
A distinctive aspect of Spora is its propagation method using Windows shortcut files. Rather than relying on autorun.inf, it hides legitimate files and folders on the desktop, removable drives, and the system drive, then replaces them with lookalike .LNK shortcuts bearing the same names and icons. When a victim opens one of these shortcuts, the original content is shown to reduce suspicion while the malware is also executed. Spora additionally copies itself as a hidden file alongside the malicious shortcuts, giving it worm-like spread via user interaction with local and removable media.
Spora primarily targets Windows systems. High-confidence reporting ties it to ransomware operations and delivery campaigns rather than to a publicly established named threat actor. Its observed behavior centers on encryption, local propagation, and deceptive execution mechanisms rather than overt command-and-control dependence during initial encryption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In recent months, the malware used in the EITest campaign has been ransomware such as Spora and Mole.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Spora adds the hidden attribute to files and folders on the desktop, in the root of removable drives and the system drive... Spora then puts Windows shortcuts with the same name and icon as the hidden files and folders as a visible replacement.
The .LNK files use the following command to execute the worm and open the original file. If the original file is a folder it will open Windows Explorer to show its contents: /c explorer.exe "<originalfile>" & type "<worm>" > "%%tmp%%\<worm>" & start "<originalfile>" "%%tmp%%\<worm>"
Gamarue, Dinihou and now also Spora use Windows shortcuts (.LNK files) instead. Spora adds the hidden attribute to files and folders on the desktop, in the root of removable drives and the system drive. Spora then puts Windows shortcuts with the same name and icon as the hidden files and folders as a visible replacement.
Gamarue, Dinihou and now also Spora use Windows shortcuts (.LNK files) instead. Spora adds the hidden attribute to files and folders on the desktop, in the root of removable drives and the system drive. Spora then puts Windows shortcuts with the same name and icon as the hidden files and folders as a visible replacement.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware delivered via the EITest campaign using Rig Exploit Kit; it infects Windows hosts, drops decryption instructions and a key to the desktop, and directs victims to the spora[.]bz payment/decryption site. The write-up notes no callback traffic from the ransomware itself beyond victim access to the payment/decryption page.
Spora is described as exhibiting worm-like propagation behavior in addition to ransomware functionality. It spreads via removable drives by hiding files and folders, replacing them with malicious .LNK shortcuts that open the original content while simultaneously executing the malware, and copying itself as a hidden executable with a generated filename.
Referenced as an earlier large-scale ransomware operation whose shutdown left space later filled by GandCrab.
Ransomware previously distributed by the EITest HoeflerText popup campaign before the shift to NetSupport Manager.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.