Monkey ransomware is a multi-platform ransomware family observed from 2025, with Rust, .NET, C++, and Golang implementations targeting Windows, Linux, and VMware ESXi environments. Variants encrypt victim data and issue ransom demands; some use hybrid cryptography, while a Rust implementation uses ChaCha20-Poly1305. Variants may terminate processes, inhibit backup and recovery mechanisms, delete shadow copies or backup data, and disable security or recovery controls. The .NET variant can steal Outlook credentials and transmit its encryption key to command infrastructure. The C++ variant can establish persistence, impair logging and endpoint defenses, and configure Microsoft Defender exclusions. The Linux and ESXi-focused Golang variant can persist through scheduled execution and disable SELinux and AppArmor. Certain variants that do not retain encryption keys function operationally as wipers despite leaving ransom notes. A variant known as Benzona also combines encryption with data-theft and publication threats. Monkey ransomware has been reported in operations attributed to the pro-Ukrainian Hacking Cat hacktivist group, although that group disputed attribution of the ransomware lockers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Hacking Cat delivered multiple Rust, .NET, C++, and Golang variants of the Monkey ransomware family against Windows, Linux, and VMware ESXi systems.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multi-platform ransomware family that terminates processes and impairs recovery before encryption. Variants use ChaCha20-Poly1305 or AES-256-CBC; some do not retain encryption keys, making them destructive wipers despite leaving ransom notes. Variants also support credential theft, privilege escalation, defense evasion, persistence, and backup deletion.
Rust-based ransomware that encrypts victim files using AES+RSA, appends extensions such as .monkey and later .benzona, drops ransom notes (e.g., How_to_recover_your_files.txt and RECOVERY_INFO.txt), claims data exfiltration, deletes shadow copies, and disables Windows recovery/repair functions.
Boot-record virus noted for consuming 1KB of conventional memory.
A boot-record virus noted for consuming 1KB of conventional memory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.