4L4MD4R, also referred to as ALAMDAR, is a Go-based ransomware family/variant identified as being based on the open-source Mauri870 ransomware code. It was observed in July 2025 during exploitation of on-premises Microsoft SharePoint vulnerabilities collectively dubbed ToolShell, including CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. Palo Alto Networks Unit 42 reported a failed exploitation attempt on July 27, 2025 that revealed a loader using PowerShell to disable real-time monitoring and bypass certificate validation before attempting to download and execute the ransomware from ice.theinnovationfactory[.]it/static/4l4md4r.exe (145.239.97[.]206). The sample was reported as UPX-packed, written in Go, and capable of decrypting an AES-encrypted payload in memory, allocating memory for the decrypted PE, and executing it in a new thread. The ransomware encrypts victim files and demands 0.005 BTC for recovery. It creates DECRYPTION_INSTRUCTIONS.html and ENCRYPTED_LIST.html on the victim desktop. The ransom note instructs victims to contact m4_cruise@proton[.]me and pay to Bitcoin wallet bc1qqxqe9vsvjmjqc566fgqsgnhlh87fckwegmtg6p; it also mentions alternative payment methods and offers to decrypt one file smaller than 5 MB as proof. Related infrastructure includes bpp.theinnovationfactory[.]it:445, to which the sample was configured to send an encrypted JSON object via POST. Reported targeting associated with ToolShell activity included internet-exposed self-hosted SharePoint servers, with broader victim reporting referencing government, education, healthcare, large enterprises, and additional observed victims in financial, logistics, and government sectors across the United States, Europe, and the Middle East. The malware has been linked in reporting to ToolShell exploitation clusters tracked by Unit 42 as CL-CRI-1040 with moderate-confidence overlap to Microsoft Storm-2603, and separate reporting also associated delivery with the threat actor Mimo. Known sample hashes reported for 4l4md4r.exe are MD5 90f71cb5df71ae3845ff81edd776b287, SHA-1 8334ed80190f525522fb47e72927f389b1680ee1, and SHA-256 33067028e35982c7b9fdcfe25eb4029463542451fdff454007832cf953feaf1e.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-53770 Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. 9.8 | On-premises Microsoft SharePoint servers are currently facing widespread, active exploitation due to multiple vulnerabilities, collectively referred to as "ToolShell" (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771). These vulnerabilities enable attackers to achieve full remote code execution (RCE) without requiring any credentials. | An investigation into ToolShell exploitation revealed the deployment of 4L4MD4R ransomware, a variant of the open-source Mauri870 ransomware.
CVE-2025-49706 Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 6.5
CVE-2025-49704 Improper control of generation of code (code injection) in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 8.8
CVE-2025-53771 Improper limitation of a pathname to a restricted directory (path traversal) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 6.5
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
An investigation into ToolShell exploitation revealed the deployment of 4L4MD4R ransomware, a variant of the open-source Mauri870 ransomware.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
In another variation, we observed the IIS Process Worker (w3wp.exe) invoking a command shell to execute a Base64-encoded PowerShell command... The command ... creates a file at ...\spinstall0.aspx
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware variant (based on the open-source Mauri870 code) that is delivered via a loader, decrypts an AES-encrypted payload in memory, and encrypts files on compromised systems while generating ransom notes and encrypted file lists; observed demanding 0.005 Bitcoin.
Go-based ransomware deployed via exploitation of Microsoft SharePoint vulnerabilities.
A new ransomware deployed via exploitation of Microsoft SharePoint servers using the ToolShell exploit.
4L4MD4r is a ransomware strain that is installed via exploitation of a Microsoft SharePoint zero-day vulnerability, encrypting files and demanding ransom.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.