Thanos is a .NET ransomware family and ransomware-as-a-service offering first identified in early 2020. Written in C#, it was marketed with a builder that allowed operators and affiliates to generate customized variants, which contributed to broad reuse and the later emergence of multiple derived ransomware families. Thanos is notable for features associated with enterprise-focused ransomware operations, including configurable payload generation and techniques intended to improve execution and hinder defenses, such as rebooting systems into Safe Mode to bypass some antivirus protections. Thanos is best known as the progenitor of several later ransomware strains and rebrands, including Prometheus, Haron, Spook, and Midas. These derivatives shared technical markers linked to the leaked Thanos builder, including common ransom-note conventions and file-format artifacts. Several of these descendant operations adopted double-extortion, combining file encryption with threats to leak stolen data via dedicated leak sites. Haron was reported as showing overlap with both Thanos and Avaddon, while Prometheus publicly claimed ties to REvil, though no solid evidence established such a relationship. Operationally, Thanos and its descendants have been associated with process and service termination to facilitate encryption, deletion of shadow copies and other recovery mechanisms, disabling or interfering with defensive tooling, and targeting a wide range of business-relevant file types. Observed variants have used strong hybrid encryption schemes and anti-recovery actions consistent with modern big-game ransomware tradecraft. The leak of the Thanos builder materially lowered the barrier to entry for other actors, enabling continued rebranding and proliferation of Thanos-derived ransomware campaigns across multiple sectors and regions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in passing as a ransomware operation that has run an affiliate program.
A ransomware family and builder used to create multiple 2021 variants including Prometheus, Haron, Spook, and Midas. The builder lowered development costs and enabled variant customization and rebranding.
Referenced as a likely codebase or design influence for Haron; the article notes strong similarity and mentions the leaked builder.
Referenced as the ransomware strain and builder from which Prometheus appears to derive its customized variant.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.