TellYouThePass is a financially motivated ransomware threat actor. It has exploited public-facing server vulnerabilities for initial access, including Apache ActiveMQ CVE-2023-46604 as a zero-day and PHP CGI CVE-2024-4577 on vulnerable Windows PHP deployments; it has also been associated with exploitation of Apache ActiveMQ and Log4j flaws. In attacks exploiting CVE-2024-4577, the actor deployed web shells, invoked mshta.exe to execute malicious HTA and VBScript content, loaded a .NET ransomware payload in memory, encrypted victim files, and demanded cryptocurrency payment for decryption. Its payload communications have used HTTP requests disguised as requests for benign web resources, indicating defense-evasion measures. TellYouThePass is also referenced under the identical alias tellyouthepass.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used CVE-2023-46604 in Apache ActiveMQ as a zero-day flaw in attacks.
Conducted ransomware activity targeting Apache ActiveMQ by exploiting CVE-2023-46604 as a zero-day.
Referenced as a threat group previously exploiting CVE-2023-46604 in Apache ActiveMQ to spread ransomware and other malware.
Ransomware activity exploiting the PHP CGI argument-injection flaw CVE-2024-4577 to execute arbitrary PHP code, establish webshell access, execute a .NET ransomware payload in memory, contact command-and-control infrastructure, encrypt victim files, and demand 0.1 BTC for decryption. The group was also reported to have previously exploited Apache ActiveMQ and Log4j vulnerabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.