H2OWATER TeAm is the operator name associated with H2OWater, a low-prevalence ransomware family written in Go and observed in 2025. The malware encrypts victim data using a hybrid cryptographic scheme combining AES-256 in CTR mode with RSA-2048, appends a distinctive H2OWATER extension to encrypted files, and delivers an HTML ransom note demanding payment in cryptocurrency. The extortion message threatens disclosure or sale of stolen data if victims do not comply, indicating a double-extortion model in addition to file encryption. The operation appears oriented toward English-speaking victims and may have opportunistic global reach rather than a narrowly defined regional focus. Reported initial access and delivery vectors include exposed remote access services, spam campaigns with malicious attachments, deceptive downloads, exploit-driven compromise, malvertising, web injects, fake software updates, botnet-assisted delivery, and trojanized installers. These behaviors support assessment of capabilities spanning initial access, defense evasion, and post-compromise extortion. Available information does not support attribution to a nation-state or a specific country of origin at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.