Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
In the case we analyzed, the attacker was able to gain access to the system via PowerShell remote control commands... The malware calls PowerShell with the cmdlet Start-Sleep to wait 5 seconds, and finally, uses the Remove-Item command to delete itself... Tactics, techniques and procedures... Execution Command and Scripting Interpreter: PowerShell T1059.001.
Finally, Ymir scans the system for the presence of PowerShell and leverages it to delete its executable to evade identification and analysis.
One interesting fact is that the sample searches for PowerShell in each subdirectory. Once PowerShell is located, the malware uses it for deleting itself... uses the Remove-Item command to delete itself from the machine... Tactics, techniques and procedures... Defense evasion Indicator Removal: File Deletion T1070.004.
Upon launch, it performs system reconnaissance by getting the system date and time, identifying running processes, and checking the system uptime, which can help determine whether it runs on a sandbox.
After reaching the main function, the malware executes another function with calls to other functions to get system information... Tactics, techniques and procedures... Discovery System Information Discovery T1082.
The malware constantly uses the memmove function while enumerating subdirectories and files inside the affected system, so they can be encrypted later... Tactics, techniques and procedures... Discovery File and Directory Discovery T1083.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a ransomware threat in Colombia.
Novel Windows ransomware strain that operates entirely from memory, performs system reconnaissance, encrypts files with ChaCha20, appends random extensions to encrypted files, drops a PDF ransom note named INCIDENT_REPORT.pdf, modifies the Windows legal notice registry value for extortion messaging, and deletes its executable via PowerShell to hinder analysis.
Ymir is a newly identified ransomware family that encrypts files using the ChaCha20 stream cipher, appends the .6C5oy2dVr6 extension, drops a PDF ransom note named INCIDENT_REPORT.pdf in affected directories, gathers system information, enumerates files and directories, and uses PowerShell to self-delete after execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.