Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
First, it copies itself into %APPDATA%\ and uses Task Scheduler to create a scheduled task that is configured to start itself each time the system is started.
It purports to have moved the user’s files to a “hidden, encrypted partition”... There is no actual verification occurring... The author is simply relying on “smoke and mirrors” in an attempt to convince victims that their files can be recovered
The batch file simply iterates through several folders within the victim’s file system... however instead of encrypting the victim’s files, it simply deletes all contents.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A fake ransomware/wiper previously observed claiming to encrypt files while actually deleting them.
A low-sophistication .NET ransomware/scareware that does not encrypt files; instead it deletes victim files and uses a fake ransom note/payment “verification” UI (images fetched via HTTP) to coerce payment despite having no recovery capability. Persists via copying to %APPDATA% and a scheduled task; drops a secondary executable and uses a batch script to delete files, shadow copies, system restore components, and modifies registry settings (e.g., disable Task Manager, Safe Mode keys), then forces shutdown and repeats on reboot.
A crude ransomware/scareware family that pretends files were moved to a hidden encrypted partition and simulates payment verification, but in reality deletes victim files rather than encrypting them and offers no recovery capability. It establishes persistence via Task Scheduler, drops components, deletes files and recovery mechanisms, displays a ransom note, and forces shutdowns on reboot.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.