Stampado is a Windows ransomware family written in AutoIt and marketed at low cost in cybercrime communities, including as a precursor or related codebase to the Philadelphia ransomware. It encrypts victim files with AES and appends a new extension to affected data, then presents a lock screen with a victim identifier and ransom instructions. The malware focuses on files within the user profile and copies itself into the roaming application-data area before establishing persistence through autorun configuration so it executes at logon.
A notable characteristic of Stampado is its coercive destructive behavior, commonly described as a "Russian Roulette" feature. After encryption, countdown timers can trigger deletion of randomly selected encrypted files, with the number of deleted files increasing over time. If the final timer expires, the malware can delete all encrypted data, increasing pressure on victims to pay quickly.
Stampado has been publicly associated with criminal sales activity and has been discussed alongside Philadelphia, which is widely regarded as a related ransomware-as-a-service offering by the same author. Similarities between Stampado and Jigsaw have been noted, particularly around timed file-deletion behavior, but any direct lineage is not firmly established. Public reporting has also indicated that a working decryptor was produced for Stampado, allowing recovery in at least some cases without paying the ransom.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware features many similarities to Stampado, another type of ransomware.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
When the Russian Roulette countdown reaches 0, a randomly selected encrypted file will be deleted. Each time the Russian Roulette countdown reaches 0, the amount of encrypted files deleted will be doubled. When the Time until total loss timer reaches zero, all of the encrypted data on the computer will be deleted.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family referenced as similar to Philadelphia; no additional behavior described in the provided content.
Ransomware family referenced as similar to Philadelphia; no additional behavior details provided in the content.
Named ransomware advertised alongside Philadelphia on the same vendor website.
A ransomware family referenced as the malware family/version from which Philadelphia is believed to derive.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.