Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
MalwareRansomware

Hakuna Matata

Hakuna Matata is a ransomware family observed in a high-severity, multi-stage Windows phishing campaign primarily targeting users and organizations in Russia. In the reported activity, a Hakuna Matata-derived payload was delivered after initial access via Russian-language business/accounting-themed archive files containing malicious LNK shortcuts. The infection chain used native Windows components including PowerShell, VBScript, registry changes, and file association hijacking rather than software exploits. The campaign fetched staged payloads from public services including GitHub and Dropbox, used repeated UAC prompts for elevation, disabled Microsoft Defender through PowerShell and registry changes, and abused the Defendnot tool to register a fake antivirus and suppress Defender. Associated payloads included reconnaissance and screenshot capture modules exfiltrating via the Telegram Bot API, plus Amnesia RAT for remote access and theft of browser, Telegram, Discord, Steam, and cryptocurrency wallet data. The Hakuna Matata-derived ransomware stage was identified as WmiPrvSE.scr. It encrypted numerous file types including documents, source code, and application assets; renamed encrypted files with the extension @NeverMind12F; dropped a ransom note named ЧИТАЙМЕНЯ.txt; changed the desktop wallpaper; and hijacked the clipboard to replace cryptocurrency wallet addresses. Reporting also states it terminated processes associated with databases, office/email clients, virtualization platforms, and security tools before encryption, disabled recovery using reagentc, wbadmin, and vssadmin, and in some cases was paired with a WinLocker component (gedion.scr) that locked the desktop and instructed victims to contact the attacker via Telegram. High-confidence artifacts mentioned in the reporting include the ransomware payload name WmiPrvSE.scr, encrypted-file extension @NeverMind12F, ransom note ЧИТАЙМЕНЯ.txt, and Telegram-based victim contact instructions.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

ACTIVITY FEED

Recent activity

4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.