Hakbit is a Windows .NET ransomware family associated with the broader Thanos ransomware lineage and ransomware-as-a-service ecosystem. First observed in late 2019, it encrypts files on individual systems and corporate networks and demands payment for recovery. Early Hakbit samples were notable for weaker or flawed encryption implementations that enabled decryption in some cases, while later related Thanos-derived variants adopted stronger RSA-based schemes that generally prevented recovery without the private key.
Hakbit and closely related Thanos builds support extensive operator customization through a builder, including configurable ransom notes and file extensions, delayed execution, self-deletion, code obfuscation, anti-analysis measures, Windows Defender interference, AMSI bypass, and victim notification features. Observed behavior includes deletion or forced removal of Volume Shadow Copy data to inhibit recovery, process termination aimed at analysis and forensic tools, delayed execution, and in some variants attempts to modify system settings related to privilege handling and recovery. Some Thanos-linked deployments also monitored newly attached storage volumes for encryption and used in-memory execution chains involving PowerShell, inline C#, and shellcode loaders.
Distribution associated with Hakbit and its Thanos-derived variants has included exposed remote administration services, spam and malicious attachments, deceptive downloads, malvertising, fake updates, exploit-driven delivery, botnet-assisted spread, and trojanized software installers. In enterprise intrusions, related variants have also been observed spreading laterally with stolen credentials over SMB and remote execution mechanisms. The family has targeted Windows environments, including state-run organizations and enterprise networks, and has evolved through multiple renamed or customized variants such as Abarcy, Corona, and Ravack before broader identification under the Thanos name. Some Hakbit-classified infections remain decryptable with public tools, but corrected later Thanos variants typically are not.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family for which Emsisoft provides a decryptor.
Hakbit is a ransomware family that inhibits system recovery by resizing the allocated storage for volume shadow copies, causing their deletion and preventing data restoration.
Ransomware family mentioned only as having code overlap with Thanos.
A .NET ransomware family derived from an early 'Ransomware Builder' / 'Thanos Ransomware Builder'. It encrypts user and corporate files, impersonates browser executables in some cases, drops ransom notes such as HELP_ME_RECOVER_MY_FILES.txt, deletes shadow copies, and has been distributed via RDP compromise, spam, malicious attachments, fake downloads, exploits, malvertising, and trojanized installers. Earlier Hakbit variants were sometimes decryptable; later corrected variants transitioned into Thanos and became undecryptable without the private RSA key.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.