Underground Team ransomware is a newly identified Windows ransomware strain reported by Cyble Research and Intelligence Labs (CRIL). It is named after its distinctive ransom note and associated Tor negotiation portal. The malware is described as a 64-bit GUI-based Microsoft Visual C/C++ executable that targets Windows systems and appears to be used in targeted intrusions, with ransom notes containing victim-specific host information. CRIL reported a ransom demand of nearly $3 million. The operators’ ransom note claims they will provide a decryptor, vulnerability insights, security recommendations, and data recovery assistance. At the time of reporting, the specific victims were unknown and no data leaks had been observed.
On execution, the ransomware uses ShellExecuteW() to launch system commands. It deletes Volume Shadow Copies via "vssadmin.exe delete shadows /all /quiet," modifies the Terminal Services registry policy at "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\MaxDisconnectionTime" with a REG_DWORD value of 1209600000, and force-stops the MSSQLSERVER service using "net.exe stop MSSQLSERVER /f /m." It enumerates system volumes using FindFirstVolumeW(), GetVolumePathNamesForVolumeNameW(), GetVolumeInformationW(), and FindNextVolumeW(), then searches for files and directories to encrypt using FindFirstFileW() and FindNextFileW(). It drops a ransom note named "!!readme!!!.txt" in multiple folders. The malware excludes specific filenames, extensions, and folders from encryption, including "\google\chrome" and "\mozilla\firefox." Notably, it encrypts files without renaming them or appending a new extension.
After encryption, Underground Team ransomware creates and executes a cleanup batch script named "temp.cmd." This script is intended to repeatedly delete a specified file, clear event logs, and delete itself to reduce forensic evidence. Observed behaviors were mapped to MITRE ATT&CK techniques including T1204, T1082, T1217, T1083, T1070, T1486, and T1490.
A separate Securonix Threat Labs report noted that encoding manipulation as part of CMD/batch obfuscation (“DOSfuscation”) was recently observed in Underground Team ransomware activity. High-confidence indicators directly mentioned in the reporting include the ransom note filename "!!readme!!!.txt," cleanup script "temp.cmd," and sample hashes: SHA-256 d4a847fa9c4c7130a852a2e197b205493170a8b44426d9ec481fc4b285a92666, SHA-1 fb4ad5d21f0d8c6755eb4addba0ac288bd2574b6, and MD5 059175be5681a633190cd9631e2975f6.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK® Techniques ... Discovery T1082 ... System Information Discovery
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation noted for using batch/DOS obfuscation techniques, including encoding manipulation (e.g., UTF-16LE) to reduce readability and evade detection.
Ransomware that enumerates system volumes and encrypts files while dropping a ransom note ("!!readme!!!.txt"). It deletes Volume Shadow Copies (vssadmin delete shadows), modifies RDP-related registry settings, stops MSSQLSERVER, and runs a cleanup script (temp.cmd) to clear traces (e.g., event logs) and remove itself. It uses an Onion-based victim portal with per-victim credentials for negotiation and includes victim host information in the ransom note.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.