Satan is a Windows ransomware family that was also operated as a ransomware-as-a-service offering, allowing affiliates to generate customized payloads while the operator managed payment infrastructure and service updates. Active since 2017, Satan evolved beyond standalone file encryption into a more capable intrusion and propagation platform, including later variants that incorporated EternalBlue-based SMB worming behavior for network spread.
On execution, Satan encrypts files across a broad set of extensions and drops ransom instructions for the victim. Reported variants rename encrypted data with Satan-specific extensions and create ransom notes in affected directories or at fixed locations. The malware has used anti-analysis checks such as virtual-machine detection, process injection into legitimate Windows processes, and post-encryption destructive actions such as wiping free space to hinder recovery. Some variants also terminate database-related services and processes before encryption to maximize impact on business systems.
Satan’s later development included automated lateral movement using publicly available EternalBlue and DoublePulsar-style tooling to scan for vulnerable SMB hosts and deploy the ransomware remotely. This gives the family both ransomware and worm-like propagation characteristics inside Windows networks. The malware also communicates with operator-controlled infrastructure to register victims or transmit host identifiers.
As a service ecosystem, Satan provided affiliates with a web-based console for configuring ransom amounts, delivery helpers, language customization, and campaign statistics. Distribution was handled by affiliates, including mechanisms such as malicious document macros and CHM-based installers, while the operator retained a share of ransom revenue. Satan is associated with financially motivated cybercrime activity and primarily targets Windows environments, with particular operational impact on enterprise networks where unpatched SMB exposure enables rapid spread.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Around November 2017, Satan devs started their plans of updating the ransomware to better fit these trends. The first step they took was to incorporate a version of the EternalBlue SMB exploit. The addition of this exploit meant that after Satan infected a computer, the ransomware would use EternalBlue to scan the local network for computers with outdated SMB services and infect them as well, maximizing an attack's impact.
AlienVault experts noticed that new versions of Satan would also scan local networks and attempt to infect other computers using one of the below exploits/methods: JBoss CVE-2017-12149 Weblogic CVE-2017-10271 Tomcat web application brute forcing
AlienVault experts noticed that new versions of Satan would also scan local networks and attempt to infect other computers using one of the below exploits/methods: JBoss CVE-2017-12149 Weblogic CVE-2017-10271 Tomcat web application brute forcing
15 distinct techniques documented for this family, organized by ATT&CK tactic.
One of these is, for example, the use of multiple packers to protect their droppers and payloads. This time however, they decided to use both MPRESS and Enigma, and even Enigma VirtualBox!
Once executed it will inject itself into TaskHost.exe and begin to encrypt the data on the computer.
When it has finished encrypting the computer, it will execute the C:\Windows\System32\cipher.exe" /W:C command to wipe all data from the unused space on the C: Drive.
The first step they took was to incorporate a version of the EternalBlue SMB exploit. The addition of this exploit meant that after Satan infected a computer, the ransomware would use EternalBlue to scan the local network for computers with outdated SMB services and infect them as well.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An early automated open-source vulnerability scanner described as the industry's first widely available tool of its kind.
An early automated open-source vulnerability scanner discussed as a historically significant security tool that democratized vulnerability discovery.
Named as an example of earlier public ransomware-as-a-service offerings.
A ransomware family previously operated by the same group and presented here as the predecessor or basis for 5ss5c. It is noted for adding EternalBlue and using similar downloader/spreader behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.