Thanatos is a Windows ransomware family first observed in 2018 and associated with multiple in-the-wild campaigns and actively developed variants. It encrypts user files across common profile directories, appends a distinctive extension to encrypted data, drops a ransom note on the desktop, and creates a Run entry so the note is reopened at logon. Thanatos copies itself into a randomly named subdirectory under the roaming application-data area before beginning encryption.
The malware’s encryption design is notably flawed. Analyses of multiple versions found that Thanatos generates a separate AES-256 key for each file using a value derived from system uptime and then discards the key instead of retaining it for later recovery. As a result, victims often cannot recover files through the operator even if a ransom is paid. Some observed variants appeared effectively destructive, including campaigns whose notes indicated that decryption was unavailable, blurring the line between ransomware and data-destruction malware.
Thanatos has been observed in several versions, including a widely distributed 1.1 branch with expanded payment options and a machine identifier included in the ransom workflow. The family showed signs of ongoing modification, including changes to ransom-note content and contact details. Researchers also identified tracking behavior in which the malware contacted a logging service to record infections.
Delivery has included direct distribution through Discord chat attachments, illustrating abuse of collaboration platforms as malware-hosting and delivery infrastructure. Thanatos was also at one point released as open source, which likely enabled derivative variants from the same code base.
The malware targets Windows systems and primarily impacts end-user data stored in common personal folders such as documents, downloads, pictures, music, and desktop content. Despite its extortion model, public analysis found limited evidence of meaningful operator revenue, and a free decryptor was developed by defenders by exploiting the malware’s weak key-generation scheme and constrained effective keyspace.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
After the encryption process is finished it will then connect to iplogger.com/1t3i37 URL in order to keep track of the amount of victims that have been infected.
The malware appears to have been delivered to the victim as an attachment to a chat message sent to the victim using the Discord chat platform. The URL hosting the attached malware is below: hxxps://cdn[.]discordapp[.]com/.../fastleafdecay.exe | When executed on victim systems, Thanatos copies itself into a subdirectory that it creates within %APPDATA%/Roaming.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware delivered via Discord-hosted payloads/links.
Ransomware cited as an earlier example of malware delivered via Discord.
Ransomware that encrypts user files (AES-256) and appends the .THANATOS extension. It derives the encryption key from system uptime (GetTickCount) and discards the key, often making victim decryption impossible even if ransom is paid. It drops a README.txt ransom note and uses a Run key to display the note at boot; it also beacons to iplogger URLs to track infections.
Ransomware that encrypts files using AES-256, appends the .THANATOS extension, drops a README.txt ransom note, and in many cases cannot restore victim data because it discards the encryption key after encryption. Some campaigns appeared intentionally destructive rather than financially motivated.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.