Mindware is a ransomware operation first observed in early 2022 and assessed to be closely related to, or a rebrand of, the earlier SFile ransomware family, also known through variants such as SFile2 and Escal. The group adopted double-extortion tactics, combining file encryption with theft of victim data and operating a public leak site to pressure non-paying victims. Victims are threatened with publication of stolen data, and the group has also warned against involving negotiators, recovery firms, or authorities. Mindware has targeted organizations across multiple sectors, including healthcare, finance, engineering, and manufacturing, and has been linked to attacks against nonprofit healthcare-related entities. Reporting also ties the broader SFile lineage to attacks against business environments and corporate networks, with historical targeting concentrated on U.S. organizations in manufacturing, engineering, automobile, investment, insurance, and retail. Technically, Mindware shares substantial code and behavioral overlap with SFile. Samples have used reflective DLL injection and in-memory loading techniques, dynamically resolving APIs through export parsing and Process Environment Block traversal rather than straightforward imports. Payloads are configured per victim, support encryption of local, removable, and network-accessible storage, and can encrypt network shares. The malware terminates many running processes to facilitate encryption, while excluding selected files, directories, and processes to preserve system stability and ensure execution. The associated intrusion tradecraft for the SFile/Mindware cluster includes brute-force access via exposed RDP, followed by ransomware deployment, encryption, and post-compromise extortion through data-leak threats. Mindware is financially motivated and fits the pattern of a targeted enterprise ransomware actor focused on high-impact intrusions, data theft, and monetization through extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group explicitly identified as using SFile/SFile2 ransomware in its operations.
A ransomware operator active from around March 2022, using double extortion, operating a public leaks site, and targeting organizations in healthcare, finance, engineering, and manufacturing.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.