Hello ransomware is a Windows ransomware family active since at least mid-2021. It encrypts victim files and appends a distinctive extension, and has been observed changing the desktop background after encryption. A notable capability attributed to this family is inhibition of recovery through direct interaction with the Windows Volume Shadow Copy Service (VSS) Coordinator via COM rather than relying solely on common command-line utilities. In observed samples, one component decrypts an embedded payload in memory and performs file encryption, while auxiliary components are used to locate a process with elevated privileges and then enumerate and delete shadow copies through the VSS Coordinator interface. This technique requires enabling SeBackupPrivilege and overlaps with legitimate backup functionality, which historically reduced straightforward detection opportunities.
Hello ransomware has also been associated with intrusion chains in which operators abused legitimate post-exploitation tooling, including Cobalt Strike, consistent with broader ransomware tradecraft involving lateral movement and hands-on-keyboard activity. Separately, the name "Hello" has also been used for an exploit kit active in watering-hole campaigns that delivered other malware families, but that is distinct from Hello ransomware. The ransomware family should therefore be distinguished from the similarly named exploit kit when tracking activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A vulnerability in an XML deserialization component within Microsoft SharePoint allowed remote attackers to execute arbitrary code... The exploit was used in malware phishing and the WickrMe/Hello Ransomware campaigns.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware whose notable feature in this report is a previously unreported COM-based Volume Shadow Copy deletion technique using the VSS Coordinator/VssCoordinator COM interface after enabling SeBackupPrivilege. It encrypts files, appends the .hello extension, changes the desktop background, and uses dropped components to prepare privileges and delete VSCs.
Referenced only as an example of a ransomware family in which China Chopper has recently been found.
Ransomware family explicitly listed as abusing Cobalt Strike.
Updated variant of the LightsOut exploit kit (noted as coming into use in 2013) that performs victim fingerprinting (OS, fonts, browser add-ons) to select efficient exploits and redirect to a malicious URL for payload delivery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.