Mario is the encryptor component used by the RansomHouse ransomware operation, also tracked in association with Jolly Scorpius. It is used in double-extortion campaigns in which attackers steal data and then encrypt systems to increase pressure on victims. Mario is closely associated with attacks against VMware ESXi environments, where encrypting a hypervisor can disrupt large numbers of hosted virtual machines simultaneously. Reported victim sectors include healthcare, finance, transportation, government, and other enterprise environments that rely on virtualized infrastructure.
Mario is assessed to be derived in part from the leaked Babuk ESXi ransomware codebase. Researchers have noted strong code overlap with Babuk, including similar file-discovery logic and use of the same default ransom note naming convention. This reuse reflects a broader trend in which multiple ransomware operators adopted Babuk-derived Linux and ESXi lockers after the 2021 source-code leak.
The malware targets virtualization- and backup-related data, including files associated with virtual machine disks, snapshots, memory, and backup products. After encrypting files, it appends an extension containing the string "mario" and drops a ransom note instructing victims on recovery procedures. More recent Mario variants introduced a more advanced two-stage encryption design using both a primary key and a secondary key, replacing earlier simpler single-pass behavior. Reported enhancements also include chunked and sparse encryption, dynamic chunk sizing, and improved buffer management, all of which increase speed against large files and complicate analysis and decryption.
Within RansomHouse operations, Mario is deployed alongside a separate management utility known as MrAgent, which automates activity on compromised ESXi hosts, including host reconnaissance, command execution, firewall disabling, and orchestration of encryption. Initial compromise in RansomHouse intrusions has been associated with spearphishing, social engineering, and exploitation of vulnerable systems, after which affiliates deploy Mario to maximize operational impact in virtualized enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mario ransomware is operated by Ransom House, a group that emerged in 2021. The samples share a very similar find_files_recursive function, including the default ransom note filename How To Restore Your Files.txt.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mario is the codename for the updated ransomware payload used by Ransomhouse, featuring dual-key encryption to make data recovery nearly impossible.
Mario is the primary encryptor component used in RansomHouse attacks, targeting virtualization-related files on ESXi hosts. It employs advanced, multi-stage encryption routines to hinder decryption and recovery, and is deployed via MrAgent.
Mario is the updated encryptor binary used by RansomHouse, implementing a multi-stage, dual-key encryption process that increases the complexity of decryption and recovery for victims.
Ransomware payload used by RansomHouse to encrypt ESXi virtual machine files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.