Abyss is a financially motivated ransomware threat group and associated Windows ransomware operation first observed in early 2023. Its operator attribution and country of origin remain unknown. Abyss has been linked to ransomware incidents affecting organizations in the United States and Germany, including manufacturing, business-services, and local-government entities. The operation has also claimed theft of victim data in at least one incident, although such criminal claims are not independently verified. Abyss is reported to gain access primarily through phishing and to expand across accessible environments through network-share and drive discovery. The malware encrypts files on local, removable, and network-accessible storage; deletes shadow copies; impairs Windows recovery settings; enumerates and terminates selected processes; and stops services associated with security tooling, databases, backup products, and enterprise applications. It also uses multi-threaded encryption, alters the desktop to display ransom instructions, and can attempt propagation via removable media. Victims are directed to negotiate a ransom payment through an anonymity network, with threats of legal and reputational consequences for involving authorities. The operation's observed behavior supports encryption-based ransomware activity, while widespread data-exfiltration activity is not established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a ransomware attack against MEMSIC, a Massachusetts-based manufacturer of sensing technology and inertial-system products.
Conducting a ransomware attack against School Facility Consultants.
Conducting a ransomware attack against the district administration of Limburg-Weilburg County in Germany.
Ransomware/extortion actor targeting healthcare with very large data-theft claims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.