WickrMe is a ransomware campaign name associated with exploitation of Microsoft SharePoint vulnerability CVE-2019-0604. Activity linked to this name involved compromise of vulnerable SharePoint servers and use of that access to install malicious payloads, including web shells, as part of follow-on intrusion and ransomware operations. Reporting places WickrMe alongside Hello ransomware in campaigns that leveraged SharePoint exploitation, indicating use in financially motivated post-compromise activity rather than as a distinct malware family with well-documented standalone tooling. The available information supports Windows enterprise environments running SharePoint as the primary affected platform. Publicly available facts in this context do not establish a fuller capability profile for WickrMe beyond its association with ransomware operations enabled by exploitation of an internet-facing server vulnerability.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The exploit was used in malware phishing and the WickrMe/Hello Ransomware campaigns.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.