Milkyway Ransomware
Milkyway Ransomware is a developing Windows-targeting ransomware strain reported by CYFIRMA (identified via underground forum monitoring) that targets organizational environments. It encrypts accessible files across infected systems, appends the ".milkyway" extension to encrypted data (e.g., "2.png" -> "2.png.milkyway"), and then displays a full-screen ransom message.
Per CYFIRMA’s reporting, the ransom note claims the victim’s servers, workstations, and backups are encrypted and unavailable, and uses coercive pressure tactics including threats to leak allegedly stolen data, report the victim to tax authorities/security services/law enforcement, share credentials/internal information, and contact the victim’s clients and partners. Victims are instructed to communicate with the attackers via a provided Outlook email address.
CYFIRMA maps Milkyway activity to multiple MITRE ATT&CK techniques and describes persistence and recovery-inhibition behaviors, including creating/modifying Windows scheduled tasks configured to run with SYSTEM-level privileges on recurring triggers (e.g., hourly or logon events), and deleting Volume Shadow Copies using commands such as "vssadmin.exe Delete Shadows /all /quiet" and "wmic shadowcopy delete /nointeractive." CYFIRMA assesses Milkyway is in an early/developing state and could evolve into a more sophisticated operation, potentially including a ransomware-as-a-service (RaaS) model.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
6 techniques
Execution
The ransomware maintains long-term presence on the system by creating and modifying Windows scheduled tasks... set tasks to run with SYSTEM-level privileges... hourly or logon events.
The following are the TTPs based on the MITRE Attack Framework ... Execution T1059 Command and Scripting Interpreter
TTPs based on MITRE ATT&CK Framework ... Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell
...exposes native Windows API functions, such as OpenProcess, VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread.
Persistence
4 techniques
Persistence
The ransomware maintains long-term presence on the system by creating and modifying Windows scheduled tasks... set tasks to run with SYSTEM-level privileges... hourly or logon events.
Persistence T1112 Modify Registry; Defense Evasion T1112 Modify Registry
Privilege Escalation
3 techniques
Privilege Escalation
The ransomware maintains long-term presence on the system by creating and modifying Windows scheduled tasks... set tasks to run with SYSTEM-level privileges... hourly or logon events.
Stealth
3 techniques
Stealth
Defense Impairment
1 technique
Defense Impairment
Discovery
2 techniques
Discovery
Command and Control
1 technique
Command and Control
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Encrypts accessible files on Windows systems, appends the ".milkyway" extension, displays a full-screen ransom message, and attempts to inhibit recovery by deleting Volume Shadow Copies (e.g., via vssadmin/wmic). Uses persistence mechanisms such as scheduled tasks and registry modifications; includes anti-analysis/anti-debug checks.
Windows-targeting ransomware that encrypts files (adding the .milkyway extension), displays a full-screen ransom note, and attempts to inhibit recovery by deleting Volume Shadow Copies (e.g., via vssadmin/wmic).
Windows-targeting ransomware that encrypts files (appending .milkyway) and presents a full-screen ransom note; attempts to inhibit recovery by deleting Volume Shadow Copies and uses persistence mechanisms (e.g., scheduled tasks/registry modifications).
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.