AtomSilo is a ransomware operation and malware family first observed around September 2021. It is associated with double-extortion activity, combining file encryption with theft of victim data and threats to publish stolen information on a leak site. The operation has remained active beyond its initial emergence and has later resurfaced with additional victim disclosures. Observed AtomSilo intrusions have involved exploitation of Atlassian Confluence for initial access, followed by installation of a backdoor through DLL side-loading. Operators then used compromised administrative accounts and WMI to execute Windows shell commands prior to ransomware deployment. These behaviors indicate a workflow that includes initial access, persistence, defense evasion, post-exploitation, and use of legitimate administrative mechanisms for execution. The ransomware payload is a 64-bit executable packed with a modified UPX packer. After execution it enumerates drives, drops ransom notes across victim directories, and encrypts files while excluding selected folders, filenames, and extensions. Its encryption routine uses partial-file encryption rather than full-file encryption, combining XOR operations with AES and appending encrypted keying material and related metadata to affected files. AtomSilo has also been observed operating a public leak site used to pressure victims through publication of stolen data. Victimology directly evidenced includes a Brazilian pharmaceutical company whose stolen data was publicly leaked, and later reporting indicates renewed activity with additional victims. The leak site has claimed the group avoids hospitals, critical infrastructure, oil and gas, education, and non-profit organizations, but such self-imposed restrictions should not be treated as reliable constraints on targeting. AtomSilo is commonly referenced as AtomSilo.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.