Khonsari is a newly identified ransomware-associated threat actor first observed exploiting CVE-2021-44228 (Log4Shell) to compromise vulnerable systems. Reporting links the actor to ransomware deployment following remote, unauthenticated exploitation of exposed Log4j-dependent applications. Khonsari has been described as a new actor rather than a well-established intrusion set, and publicly available high-confidence information about its broader infrastructure, affiliations, victimology, or geographic origin remains limited. Available reporting also noted anomalies suggesting the operation may in some cases have functioned more like a destructive wiper than conventional ransomware, raising uncertainty about whether financial extortion was the sole or primary objective. High-confidence aliases or sub-groups beyond the Khonsari name are not established in the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.