Pandora is a financially motivated ransomware operation that emerged in early 2022 and targets corporate Windows environments. The group is associated with a Windows ransomware family that encrypts files, appends a Pandora-themed extension to impacted data, and drops ransom notes across affected directories. Pandora is known for double-extortion operations, combining file encryption with data theft and threats to publish stolen information on a leak site. Pandora’s tooling demonstrates a strong focus on defense evasion and operational impact. Reported capabilities include deletion of shadow copies to inhibit recovery, in-memory patching of AMSI to reduce anti-malware visibility, and patching of ETW functions to impair telemetry. The malware also uses packing and anti-analysis measures such as modified UPX-based protection, string encoding, control-flow obfuscation, opaque predicates, and obfuscated API and function calls. For encryption at scale, Pandora enumerates drives and volumes, mounts otherwise unmounted storage, and uses multithreading and Windows I/O completion mechanisms to accelerate filesystem traversal and encryption. It also leverages Windows Restart Manager APIs to identify and terminate processes locking target files, increasing encryption coverage. The malware avoids encrypting selected system-critical files, folders, and extensions to preserve system operability long enough for ransom demands to be delivered. Victimology indicates targeting of corporate entities, with observed victims including organizations in the United States and Japan, including technology and real-estate-related entities and a law firm. Reporting has also noted tactical and victim-overlap similarities with ROOK, and Pandora has been assessed by some researchers as a possible rebrand or successor of ROOK, though that relationship is not conclusively established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a ransomware actor previously observed exploiting VMware Horizon.
Ransomware operations using double extortion against corporate networks, including data theft, file encryption, and leak-site pressure on victims.
Ransomware operations involving file encryption, ransom-note deployment, and suspected double extortion with data exfiltration and leak-site pressure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.