Bart is a Windows ransomware family associated with TA505 and historically linked to the same criminal ecosystem that distributed Dridex and Locky. It emerged in 2016 and was observed as a secondary payload delivered by Rockloader during TA505 email-driven malware operations. Bart is notable for being able to encrypt victim files without requiring command-and-control communication during the encryption phase, distinguishing it from some earlier ransomware families that depended more directly on online key exchange or live infrastructure. It was used in financially motivated campaigns intended to encrypt files and coerce victims into paying for recovery, but it did not achieve the same prominence as Locky. Bart is also notable for having had publicly available decryptor support, indicating that at least some variants became recoverable without ransom payment. High-confidence reporting ties Bart to spam-based distribution activity by TA505, typically through malicious email attachment chains used by that actor’s broader ransomware campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family for which AVG provides a decryptor.
Ransomware mentioned only as historical background on TA505 activity.
Ransomware with a Locky-like ransom screen; notable for being able to encrypt without contacting C2; observed only briefly (one day) in TA505 activity.
Ransomware previously introduced by the same group; first seen in email and later spread via exploit kit campaigns. Its payment portal is described as visually similar to Jaff's.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.