Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The threat actor exploited CVE-2021-20039 to gain access (Authenticated Command Injection).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Revealing the Abyss Ransomware Executive Summary Abyss Ransomware emerged in early 2023... It is typically spread through phishing emails... Once it has gained access, Abyss encrypts critical files in the victim’s network using lateral movement techniques and advanced cryptographic algorithms.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The ransomware opened the ‘HKEY_CURRENT_USER\Control Panel\Desktop’ registry path using the RegOpenKeyExW function. It edited the ‘WallpaperStyle’ and ‘TileWallpaper’ entries to 0 using the RegSetValueExW API.
It then goes through a list of service names... and tries to open each service using the OpenServiceA function. Then, for each service, it queries the service status using the QueryServiceStatusEx function.
The ransomware uses the CreateToolhelp32Snapshot function to create a snapshot of current processes running on the host system.
The ransomware will destroy the contents of files and then change their extension to .XPbS1.
If a match is found, the malware uses the OpenProcess function to open and handle the process and the TerminateProcess function to terminate the process.
The goal of these commands is to prevent the victim from entering recovery mode and to remove shadow copies to prevent data restoration from backups. /c vssadmin.exe delete shadows /all /quiet /c wmic SHADOWCOPY DELETE /c bcdedit / set{ default } recoveryenabled No /c bcdedit / set{ default } bootstatuspolicy ignoreallfailures
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family first reported in early 2023 that spreads via phishing, encrypts files across local and network-accessible systems, deletes shadow copies, impairs recovery options, terminates or interferes with security, database, backup, and enterprise services, drops ransom notes, changes wallpaper, and attempts lateral movement via SMB shares and external drives.
A cross-platform ransomware family targeting Windows, Linux, and especially VMware ESXi environments. It uses Salsa20 encryption, appends .abyss or .crypt extensions, drops the ransom note WhatHappened.txt, disables services, alters boot configuration for persistence/evasion on Windows, and uses esxcli to shut down VMs for encryption on Linux. It also conducts multi-extortion by exfiltrating data and threatening publication on a TOR leak site.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.