Philadelphia is a Windows ransomware family introduced in 2016 and commonly described as a low-cost ransomware-as-a-service offering derived from or closely related to Stampado. Written in AutoIt, it was marketed to low-skill operators and gained attention for lowering the barrier to entry for targeted extortion campaigns. Philadelphia encrypts victim files, has been reported to use AES-256 for file content encryption and RC4 for file name encryption, and is associated with timed file-deletion threats intended to pressure payment. Operators can customize ransom demands and victim messaging, including organization-specific ransom notes, through server-side configuration and campaign management features.
Philadelphia has been distributed through multiple delivery channels, including spearphishing and broader malspam campaigns, malicious attachments and links, macro-enabled Office documents that invoke PowerShell, exploit kits, and trojanized software offered through cracking or keygen ecosystems. Targeted campaigns have used healthcare-themed lures and spoofed internal-looking emails, and healthcare organizations have been repeatedly identified among victims. The malware has also been advertised and sold in cybercrime communities as a turnkey kit.
The family has been associated with financially motivated criminal activity, including use by TA505 in some campaigns, though it was also available as an off-the-shelf commodity payload to other actors. Reporting has described flexible operator control over ransom amount, payment workflow, and victim identifiers, as well as a companion management feature allowing attackers to selectively decrypt files for free. Philadelphia is best characterized as commodity ransomware that enabled both opportunistic and targeted attacks against Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ils utiliseraient soit des trojans bancaires (notamment Dridex et TrickBot jusqu’à début 2018), soit des rançongiciels (notamment Locky, GlobeImposter et Philadelphia)
...as well as several ransomware strains including Locky, BitPaymer, Philadelphia, GlobeImposter, and Jaff on their targets' computers...
"Philadelphia" is a type of encrypting ransomware malware created in 2016... sold as-a-service by The Rainmaker... encrypts computer files and gradually deletes them, demanding a bitcoin ransom...
10 distinct techniques documented for this family, organized by ATT&CK tactic.
"It was intended to cause harm and generate income through ... compromised websites..."
"It was intended to cause harm and generate income through ... Trojanized downloads..."
According to Fox-IT, the hackers were able to infiltrate the university's systems via two phishing e-mails that were opened on two UM systems on October 15 and 16.
Three document icons pertaining to patient information are present in the file—and if a user clicks any of them, the ransomware is executed.
the site redirects to a personal storage site to download a malicious document that contains the targeted healthcare organization's logo and a signature of a medical practitioner from that organization as bait. Three document icons pertaining to patient information are present in the file—and if a user clicks any of them, the ransomware is executed.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Encrypting ransomware (sold as-a-service) that encrypts local user files and applies additional pressure by gradually deleting them, demanding Bitcoin for decryption; includes a "mercy" option to decrypt for free.
Encrypting ransomware (RaaS) introduced in September 2016 that encrypts local user files, may gradually delete them to increase pressure, and demands Bitcoin for decryption; includes a notable 'mercy' option allowing free decryption via a companion site ('Philadelphia Headquarters').
Ransomware family mentioned as one of several strains historically deployed by TA505.
Ransomware customized for targeted campaigns; briefly distributed by TA505 in a large spam campaign (July, year not explicitly stated in text).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.