VHD is a C++ ransomware family assessed to be owned and operated by the Lazarus Group, a DPRK-linked threat actor. It emerged in 2020 as part of Lazarus activity that blended financially motivated extortion with tradecraft more commonly associated with advanced persistent threat operations.
VHD encrypts files across connected disks and is designed to maximize impact on enterprise environments. Reported behavior includes terminating processes that can lock files, including services associated with Microsoft Exchange and SQL Server, deleting volume-shadow-related data directories, and resuming encryption if interrupted. It uses a hybrid encryption scheme combining AES-256 and RSA-2048. Analysis has noted implementation weaknesses, including use of AES in ECB mode and insecure handling of cryptographic material for some large files, which may permit partial recovery in certain cases.
Observed intrusions involving VHD were highly targeted rather than characteristic of broad affiliate-driven ransomware deployment. In one case, VHD was paired with a custom propagation utility that brute-forced SMB using victim-specific administrative credentials, mounted remote shares, copied the ransomware laterally, and executed it via WMI, resembling worm-like spread inside the victim network. In another case, attackers reportedly gained initial access by exploiting a vulnerable VPN gateway, escalated privileges, deployed the MATA backdoor, compromised Active Directory, and then distributed VHD across the environment within roughly ten hours. The use of MATA, which has been linked to Lazarus, and the absence of evidence that VHD was a commercially shared ransomware product support attribution of VHD to Lazarus-operated campaigns.
VHD is associated with extortion-focused operations in enterprise networks and has been discussed alongside other Lazarus tooling such as Manuscrypt, Sharpknot, and MATA. Its significance lies less in novel cryptographic design than in its integration into disciplined, hands-on intrusions conducted by a state-linked actor pursuing financially motivated objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2020, the group tried its hand at the big extortion game with the VHD ransomware family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware sample from a DPRK ransomware-family investigation, compared against BEAF for code and audio-profile similarities and differences.
Ransomware referenced as part of Lazarus’ broader toolset; no further technical detail provided in this content.
Ransomware written in C++ that encrypts files across connected disks, deletes restore-point related folders, stops processes such as Microsoft Exchange and SQL Server, and uses AES-256 in ECB mode with RSA-2048. It also supports resuming interrupted encryption and in some cases stores cryptographic material on disk in clear text.
Ransomware family used by Lazarus in extortion activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.