Ouroboros is a Windows ransomware family associated in reporting with Iranian actors and notable for apparent code lineage with later ransomware families including TeslaRVNG/Yakuza and VoidCrypt. It encrypts victim files and has been identified by multiple security vendors under ransomware detections tied to the Ouroboros name. Genealogy reported by researchers places Ouroboros as an earlier branch in a development line that later evolved into TeslaRVNG and Secles, while separate analysis has noted shared development elements between Ouroboros and VoidCrypt, suggesting reuse of code or builder components across related ransomware projects.
The family is primarily relevant as a file-encrypting threat rather than a stealth access platform. Available reporting supports its role in extortion-oriented attacks against Windows systems, with downstream related families using hybrid AES and RSA encryption, ransom notes, and recovery-inhibiting actions such as deleting shadow copies and impairing restoration options. Ouroboros has also appeared in sanctions-risk discussions because of its alleged linkage to Iranian operators, making ransom payments involving this family potentially legally sensitive for affected organizations subject to U.S. sanctions regimes.
High-confidence public details on Ouroboros-specific delivery chains are limited in the available material. However, its documented relationships to TeslaRVNG and VoidCrypt place it within an ecosystem of ransomware families commonly distributed through exposed remote access services, malicious email campaigns, deceptive downloads, exploit-driven intrusion, fake updates, and trojanized installers. The strongest supported characterization is that Ouroboros is a Windows ransomware family with extortion objectives, code relationships to several later ransomware strains, and reported ties to Iranian threat activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an ancestral/family predecessor in the genealogy of TeslaRVNG.
Ransomware family listed as carrying sanctions risk because it is linked to Iranian actors.
Referenced as a related ransomware family from which VoidCrypt may have borrowed code or lineage; AV detections also frequently classify VoidCrypt variants as Ouroboros.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.