Mamba, also known as HDDCryptor, is a Windows disk-encrypting ransomware family that denies access by encrypting entire drives rather than selectively encrypting user files. It is notable for weaponizing the legitimate open-source full-disk encryption utility DiskCryptor, using it to encrypt system and data partitions and render the operating system unbootable. The malware installs DiskCryptor components, deploys a malicious service to continue execution across reboots, and modifies the boot process by replacing or altering the master boot record so that a ransom screen is shown before normal startup. Reported variants perform the attack in multiple stages, including installing the encryption components, rebooting to complete driver setup, then rebooting again after disk encryption to present the ransom demand.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Once it infects a machine, it overwrites the host computer's Master Boot Record (MBR) with its own variant, and from there, it will now be able to encrypt the hard drive.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware that overwrites the Master Boot Record (MBR), manipulates the boot process, and encrypts entire disk partitions rather than only individual files. It also encrypts files on the computer and mapped network drives, preventing the PC from booting unless a decryption key is provided.
2FA-focused phishing kit; content discusses URL-parameter-based detection improvements (base64-encoded parameters).
A ransomware family mentioned as a disk encrypter.
Ransomware that leverages the open-source DiskCryptor and writes a custom bootloader to the MBR; noted as gaining traction with new variants (including one found in H2 2019).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.