Spook is a ransomware variant and associated extortion operation that emerged in September 2021 and is linked to the leaked Thanos ransomware builder. It is part of a cluster of Thanos-derived ransomware families that also includes Prometheus, Haron, and Midas. Spook used the common Thanos tradecraft of encrypting victim files, dropping ransom notes in text and HTA formats, and leveraging a leak site to pressure victims through double extortion. Technical reporting ties Spook to the Thanos lineage through shared implementation markers and operational patterns seen across related variants. These include use of the Thanos builder, common ransom-note key identifiers, a characteristic marker appended to encrypted files, and similar ransom-note naming conventions. Reporting on the broader Thanos-derived cluster also indicates operators commonly terminated processes that could interfere with encryption and disabled protections associated with anti-ransomware tooling. Spook should be understood primarily as a financially motivated cybercriminal ransomware operation rather than a nation-state actor. Available reporting supports its role in data-theft-backed ransomware extortion, but does not provide high-confidence attribution to a specific country of origin, distinct sub-groups, or a well-defined victimology beyond its participation in the broader Thanos-derived ransomware ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparative example of another ransomware group weaponizing an information stealer-related toolchain.
A Thanos-derived ransomware variant that used double extortion and maintained its own leak site.
Named as a likely Prometheus/Thanos-derived variant discussed in the update block.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.