Yashma is a Windows ransomware family first observed in 2022 and widely assessed as a rebranded descendant of the Chaos ransomware line, particularly Chaos v5. It is implemented as a 32-bit .NET executable and has also appeared under rebranded variants such as SolidBit. Yashma has been linked to multiple derivative families in the broader Chaos ecosystem and has been used both directly and through customized affiliate-operated builds.
Yashma encrypts victim files with AES and is notable for improving on earlier Chaos variants by supporting encryption of larger files rather than destroying files above a size threshold. It commonly establishes persistence by copying itself into a user profile location and configuring autorun mechanisms through the Windows Run key and shortcuts or startup artifacts. The malware typically prevents duplicate execution through mutex or instance checks. It also performs extensive anti-recovery actions, including deletion of shadow copies and backup catalogs, disabling recovery-related features, and stopping backup-associated services. Some observed variants overwrite original file contents before deletion, complicating forensic recovery.
Operationally, Yashma variants have shown additional defense-evasion features such as obfuscation, anti-debugging behavior, and in some cases external retrieval of ransom-note content to reduce static detection opportunities. Certain campaigns have mimicked well-known ransomware branding, including WannaCry-themed ransom notes and wallpaper changes, while others have imitated LockBit-style presentation despite being Chaos/Yashma-derived. The malware can also alter desktop appearance and drop ransom notes across affected directories.
Observed samples include logic to avoid execution on systems using Azerbaijani or Turkish language settings, a trait shared with other Chaos-derived families. Reporting also indicates Yashma can enumerate drives and spread to network-accessible locations, enabling limited lateral movement across reachable storage resources.
Delivery has included social-engineering lures and phishing-style distribution, as well as trojanized applications hosted on code-sharing platforms and disguised as gaming or social-media tools. In at least one campaign, lure executables launched PowerShell to weaken Microsoft Defender protections before deploying a Yashma-derived ransomware payload.
Yashma has been used by multiple financially motivated actors rather than a single exclusive operator. Customized campaigns have targeted victims across multiple geographies, including English-speaking countries, Bulgaria, China, and Vietnam, and some operators have advertised affiliate programs consistent with ransomware-as-a-service activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 1 Discovery (TA0007) T1016: System Network Configuration Discovery
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 1 Discovery (TA0007) T1016: System Network Configuration Discovery T1083: File and Directory Discovery T1135: Network Share Discovery T1049: System Network Connections Discovery
This ongoing attack uses a variant of the Yashma ransomware likely to target multiple geographic areas by mimicking WannaCry characteristics.
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 6 Impact (TA0040) T1486: Data Encrypted for impact T1489: Service Stop
The ransomware deletes the shadow copies and backup, while also disabling the recovery mode and task manager. vssadmin delete shadows /all /quiet & wmic shadowcopy delete bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no wbadmin delete catalog -quiet
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related content as a ransomware variant.
Referenced as a ransomware family whose builder leak contributed to commoditization and tracking difficulties.
Referenced as a Chaos ransomware builder variant (not related to the newly emerged Chaos RaaS group).
A ransomware family and rebranded version of Chaos ransomware V5. In this campaign, the observed variant downloads its ransom note from an actor-controlled GitHub repository via an embedded batch file, establishes persistence via the Run registry key and a .url startup file pointing to %AppData%\Roaming\svchost.exe, encrypts files, changes the victim wallpaper, and includes anti-recovery behavior by wiping and deleting original files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.