Venus is a Windows ransomware family used in intrusions that have been linked to operators also deploying Crysis. Observed attacks commonly begin with compromise of externally exposed Remote Desktop Protocol services through brute-force or dictionary attacks against weak credentials. After gaining access, operators use the foothold for credential theft, internal reconnaissance, and lateral movement, including deployment of tools such as Mimikatz and NirSoft utilities to identify additional reachable systems and harvest account data before encryption.
On execution, Venus encrypts victim files and appends a dedicated extension to affected data. It drops an HTML ransom note, alters the desktop to present extortion instructions, and is associated with claims that data was stolen in addition to file encryption. Prior to encryption, it terminates a range of business, office, mail, and database-related processes to maximize file access. It also excludes selected system and application paths and avoids encrypting certain self-referential note-related names.
Venus includes recovery-inhibition behavior typical of modern ransomware. It deletes volume shadow copies and modifies recovery-related settings through native administrative utilities to hinder restoration. In reported incidents, Venus was sometimes deployed after an attempted Crysis encryption failed, indicating it can serve as an alternate locker within the same intrusion workflow. The family has also been referenced as an influence on later ransomware development, including cryptographic design elements borrowed by GenieLocker. Victimology in documented cases reflects opportunistic enterprise targeting via exposed remote administration services rather than a narrowly defined sector focus.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Using the collected account information, lateral movement can occur to other systems within the network. In an actual attack case involving Crysis, the threat actor used RDP for lateral movement into other systems within the network. | Crysis and Venus are both major ransomware types known to target externally exposed remote desktop services. Actual logs from the AhnLab Smart Defense (ASD) infrastructure also show attacks being launched through RDP.
The threat actor ultimately executed Crysis to encrypt the system, and after recognizing failure after a few hours, retried the attack using Venus.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family cited as inspiration for GenieLocker's encryption scheme.
Referenced as a ransomware family whose cryptographic scheme and approaches were borrowed by GenieLocker.
Ransomware used in RDP-based intrusions. It encrypts files with the .venus extension, terminates processes such as Office, email, and database applications to maximize encryption impact, deletes volume shadow copies, changes the desktop, and drops a README ransom note claiming data theft and demanding contact within 48 hours.
Web shell used to maintain redundant access to compromised web servers abused as C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.