HavanaCrypt is a .NET ransomware family that masquerades as a Google software update component to reduce suspicion during execution. It employs anti-virtualization and anti-analysis checks, including inspection for VMware- and VirtualBox-related artifacts, and may terminate when it detects a virtualized environment. The malware is obfuscated and hides its execution window, indicating an emphasis on defense evasion.
After launch, HavanaCrypt weakens host defenses by downloading and executing a batch script that modifies Microsoft Defender preferences. It also terminates a range of running processes, including business and database-related applications, to increase the number of files available for encryption. To inhibit recovery, it deletes shadow copies and removes restore points.
The ransomware establishes persistence by copying itself into startup-related locations and creating additional startup artifacts. Before encryption, it fingerprints the victim system using hardware information to derive a unique identifier, then communicates with command-and-control infrastructure to obtain encryption-related material. It also stores locally generated RSA key material for use in its workflow.
HavanaCrypt encrypts files and appends a dedicated extension to affected data while excluding some directories and file types. Reported samples did not drop a ransom note, suggesting the family may have been immature or still under development at the time it was observed. The malware is associated with Windows environments and demonstrates a conventional ransomware playbook centered on defense evasion, persistence, host profiling, and file encryption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
After it terminates all relevant processes, HavanaCrypt queries all available disk drives and proceeds to delete the shadow copies
HavanaCrypt has four stages of checking whether the infected machine is running in a virtualized environment.
First, it checks for services used by virtual machines such as VMWare Tools and vmmouse.
HavanaCrypt then checks the AutoRun registry to see whether the “GoogleUpdate” registry is present.
HavanaCrypt also terminates certain processes that are found running in the machine
Before it proceeds with its encryption routine, HavanaCrypt gathers certain pieces of information and sends them to its C&C server... The pieces of machine information that HavanaCrypt gathers include: The number of processor cores, The processor ID, The processor name, The socket designation, The motherboard manufacturer, The motherboard name, The BIOS version, The product number
HavanaCrypt replaces the string “index.php” with “ham.php” to send a GET request to its C&C server ... using “Havana/1.0” as the user agent... After gathering all the necessary machine information, HavanaCrypt sends it via a POST request to hxxp://20[.]227[.]128[.]33/index.php
HavanaCrypt encrypts files and appends “.Havana” as a file name extension.
HavanaCrypt queries all available disk drives and proceeds to delete the shadow copies and resize the maximum amount of storage space to 401 MB. It also checks for system restore instances via Windows Management Instrumentation (WMI) and proceeds to delete them by using the SRRemoveRestorePoint function.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly identified .NET ransomware family that masquerades as a Google Software Update application, uses anti-virtualization checks, downloads and executes a batch file to weaken Windows Defender protections, gathers host fingerprinting data, communicates with a C2 at 20[.]227[.]128[.]33, generates/stores RSA material, encrypts files with the .Havana extension, deletes shadow copies and restore points, and logs encrypted directories in foo.txt. The report notes it uses KeePass Password Safe modules during encryption and may still be under development because it does not drop a ransom note.
Ransomware referenced for anti-VM checks by enumerating virtualization-related services (e.g., VMTools/VMware Tools) to evade dynamic analysis.
Ransomware referenced here for anti-virtualization checks (e.g., enumerating VM-related services such as VMware Tools/VMTools) to evade analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.