Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
his alias JimJones had spent 2019 and 2020 on the Exploit forum hawking malware development and a dev shop called Shtazi-IT... In October 2024, a Moscow court gave Ermakov two years of restriction of freedom under Article 273(2), Russia's malware statute, for co-writing SugarLocker and selling it to a buyer with a Tor control panel attached.
First, to create a Tor browser directory on the desktop, the desktop path is collected according to the Integrity Level of the current token. System Privileges: Finds user logon sessions and collects the user profile path
For the purpose of classifying an infected device, an ID is created by combining specific values... Serial number of the physical drive (PhysicalDrive0) Operating system installation date (InstallDate) Computer name (GetComputerNameW)
When encrypting the network drive, the target network drive path is logged and encrypted by classifying the resource type through the DisplayType of the network resource
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware that the article says Ermakov co-wrote and sold via the Shtazi-IT shopfront, with a Tor-based control panel attached.
Delphi-based ransomware offered as ransomware-as-a-service. It encrypts local, removable, desktop, and optionally network-shared files; supports multiple file-encryption modes (SCOP, RC6, Salsa20) and key-encryption modes (RSA, ElGamal); stores victim data in the registry; periodically exfiltrates infected-host information to a C2 server; downloads a Tor browser package for victim negotiations; appends the .encoded01 extension; and drops ransom notes named BackFiles_encoded01.txt.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.