Khonsari is a ransomware family first publicly observed during the early wave of exploitation of the Apache Log4j Log4Shell vulnerability (CVE-2021-44228) in December 2021. It was delivered to vulnerable internet-facing Java applications through remote code execution enabled by Log4Shell, making it one of the earliest ransomware payloads associated with that mass-exploitation event. Reported attack chains involved retrieval of a malicious Java component that then downloaded and launched a .NET ransomware payload on compromised systems.
Khonsari is associated with file encryption and ransom-note deployment, and the family name was reflected in the encrypted-file extension and ransom messaging. At the same time, multiple analysts noted anomalies in the ransom note, including the apparent absence of credible attacker contact details, leading to assessments that some observed samples may have functioned more like destructive wipers than conventional profit-driven ransomware. Other reporting assessed that the malware used valid encryption, indicating genuine impact to victim data even if monetization and operator tradecraft appeared immature.
Khonsari has been discussed primarily in the context of opportunistic exploitation of unpatched Log4j-exposed systems rather than as a long-established ransomware operation with a well-documented affiliate ecosystem. It was one of several malware payloads rapidly deployed via Log4Shell alongside coin miners, botnets, remote access tools, and other ransomware families. Public reporting ties Khonsari to exploitation of vulnerable Java server applications, while the ransomware payload itself was a .NET binary affecting Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Mal/ExpJava-AL, Mal/ExpJava-AN, Mal/ExpJava-AO (Khonsari downloaders) ... Troj/Khonsari-A (new)
"A query for the Khonsari ransomware family that is currently exploiting the log4j vulnerabilities is also available..."
"A query for the Khonsari ransomware family that is currently exploiting the log4j vulnerabilities is also available..."
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Khonsari-related downloaders and a Khonsari payload were detected in Log4j exploit attempts.
Referenced only for comparison; the article explicitly states there is no evidence of any link between Khonsari and this STRRAT sample.
Ransomware family publicly reported as a payload delivered through Log4Shell exploitation.
Ransomware strain reported as an early adopter of Log4Shell exploitation shortly after public PoC release.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.