Mamba is a ransomware operation known for rendering victim systems inaccessible by leveraging full-disk encryption rather than conventional file-by-file ransomware encryption. It has been associated with the use of DiskCryptor to lock victim machines, a technique that can leave systems unbootable or otherwise unusable until recovery actions are taken. Mamba has also been identified among ransomware groups whose proceeds were laundered through cryptocurrency mixing services. Based on the available facts, Mamba is best characterized as a financially motivated ransomware actor focused on extortion through system encryption.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a ransomware gang that used Cryptomixer to launder ransom payments.
Referenced as a ransomware operation known for using DiskCryptor to lock victim machines by overwriting or encrypting disk access at a lower level.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.