TellYouThePass is a ransomware family active since at least 2019. It has been observed in multiple intrusion campaigns exploiting internet-facing remote code execution vulnerabilities, including Apache ActiveMQ CVE-2023-46604 and PHP for Windows CVE-2024-4577, to gain execution on exposed servers and deploy ransomware payloads. A .NET variant has been documented in exploitation chains targeting vulnerable Windows-based PHP deployments, including default-style XAMPP environments where PHP CGI exposure enables remote compromise.
The malware is associated with financially motivated ransomware activity and has been linked to a threat cluster commonly referred to as the TellYouThePass ransomware gang. Observed operations indicate opportunistic targeting of publicly reachable infrastructure rather than a narrowly defined vertical, with emphasis on vulnerable enterprise servers. In campaigns exploiting PHP for Windows, attackers used crafted requests to trigger native Windows utilities and execute staged script content that decoded and loaded the ransomware into memory.
TellYouThePass’s primary objective is file encryption for extortion. Its known role in observed campaigns is as the final ransomware payload delivered after successful exploitation of exposed services. Reporting also places it among several malware families historically deployed through exploitation of Apache ActiveMQ, showing that it is part of a broader ecosystem of post-exploitation monetization following server compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-4577 (CVSS v3.1 skóre 9,8) Kritická zraniteľnosť jazyka PHP, ktorá umožňuje vzdialené vykonávanie kódu na zraniteľných PHP serveroch injektovaním premenných. Chyba súvisí s konverziou kódovania znakov cez funkciu Best-Fit pre Windows... PHP modul CGI môže tento výstup interpretovať ako premenné, resp. príkazy PHP. | Zraniteľnosť je v súčasnosti aktívne zneužívaná na šírenie ransomvéru TellYouThePass... Analýza spoločnosti IMPERVA ukázala, že sa jedná o .NET variant ransomvéru TellYouThePass. Táto rodina ransomvéru je aktívna už od roku 2019.
Red Canary detected an adversary executing discovery commands on dozens of cloud-based Linux endpoints vulnerable to a critical remote code vulnerability (CVE-2023-46604) in Apache ActiveMQ... Security researchers have previously identified adversaries exploiting CVE-2023-46604 for malware deployment, to spread TellYouThePass, Ransomhub and HelloKitty ransomware, along with Kinsing... Finally, the adversary used curl to download two ActiveMQ JAR files... These two JAR files constitute a legitimate patch for CVE-2023-46604. | Security researchers have previously identified adversaries exploiting CVE-2023-46604 for malware deployment, to spread TellYouThePass, Ransomhub and HelloKitty ransomware...
6 distinct techniques documented for this family, organized by ATT&CK tactic.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used by the TellYouThePass gang; the content notes it targeted Apache ActiveMQ vulnerability CVE-2023-46604 as a zero-day.
Ransomware that encrypts files and demands payment, spread via exploitation of Apache ActiveMQ vulnerability.
Ransomware family mentioned as previously exploiting CVE-2023-46604 in Apache ActiveMQ.
Ransomware observed being spread through exploitation of Apache ActiveMQ vulnerability CVE-2023-46604.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.