Beast Ransomware is a ransomware-as-a-service (RaaS) operation active since June 2024 and believed to be a successor to the Monster Ransomware group. It supports double extortion through a leak site named BEAST LEAKS. Reporting linked to an exposed operator directory showed the group’s workflow from reconnaissance through encryption and indicated targeting of both Windows and Linux environments, including Linux or VMware ESXi systems, based on the presence of Windows and Linux encryptors (encrypter-windows-cli.x86.exe and encrypter-linux-x64.run).
Observed tooling and behavior included reconnaissance and network mapping with Advanced IP Scanner and Advanced Port Scanner; file discovery with Everything.exe and FolderSize-x64; credential theft using Mimikatz, LaZagne, Automim, a registry modification file named enable_dump_pass.reg to force cleartext password storage in memory, and a Kerberos.ps1 script believed to support Kerberoasting; lateral movement with PsExec and OpenSSH for Windows; persistence via AnyDesk; and data exfiltration using MEGASync to upload stolen data to Mega[.]nz, as well as WinSCP and Klink. Backup destruction and anti-recovery activity included a disable_backup.bat script used to delete volume shadow copies and disable Windows backups. A file named CleanExit.exe was suspected to wipe logs and delete tools used during the intrusion. Team Cymru assessed that much of Beast’s tooling is not novel, but the exposed toolkit provides defenders with actionable indicators and tradecraft to detect and disrupt attacks before encryption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-service malware used in double extortion attacks. The operators conduct reconnaissance, credential theft, lateral movement, persistence, and data exfiltration before deploying Windows and Linux/ESXi encryptors.
Beast Ransomware is a newly emerged ransomware-as-a-service (RaaS) threat that utilizes the ChaCha20 encryption algorithm and employs stealthy techniques to delete Volume Shadow Copies (VSS), making file recovery more difficult for victims.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.