Hansom is a Windows ransomware component observed as a plugin within the CRAT malware ecosystem and associated with intrusion activity linked by multiple researchers to the Larva-26005 cluster and Lazarus-like tradecraft. It has been used in operations targeting Korean-speaking entities and South Korean users, appearing alongside CRAT and later discussed in connection with Xctdoor-related activity.
Unlike conventional ransomware that directly encrypts victim files in place, Hansom archives targeted files into password-protected RAR containers, deletes the originals, encrypts the archive passwords with an embedded RSA public key, and then restores the archive under the original filename with an added encryption marker. It targets a broad range of document, archive, image, executable, database, certificate, and configuration file types while excluding selected files and folders to preserve operating system stability. After processing files, it drops a ransom note and has also been observed dropping a decryptor onto the victim desktop.
Hansom includes several defensive-disruption and persistence behaviors. It suppresses Windows Defender notifications, terminates the Microsoft Defender antimalware process, disables Task Manager, establishes persistence through a Run-key mechanism that launches the ransomware DLL via Regsvr32, and deletes shadow copies after encryption to hinder recovery. In the broader CRAT framework, the plugin can be delivered and activated after initial compromise by the RAT, which supports modular deployment of additional capabilities.
Historical CRAT intrusions associated with Hansom have been tied to malicious Hangul Word Processor documents exploiting CVE-2017-8291, phishing-themed lures, and later reporting connected related activity to spear-phishing LNK delivery chains and trojanized software used against South Korean targets. Hansom was first observed in the wild in 2020 as part of this modular intrusion set.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"Xctdoor와 과거 CRAT 공격 사례의 연관성 분석 (Larva-26005)" published by Ahnlab. #CVE20178291, #Phishing, #LNK, #Xctdoor, #CRAT, #Larva26005, #Hansom
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
One of the plugins is a ransomware known as "Hansom."
"Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)" published by Ahnlab. #CVE20178291, #Phishing, #LNK, #Xctdoor, #CRAT, #Larva26005, #Hansom
14 distinct techniques documented for this family, organized by ATT&CK tactic.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware mentioned in connection with the broader attack cluster/tags in the referenced post.
Named ransomware mentioned in the reference alongside Xctdoor, CRAT, and Larva-26005.
감염 시스템을 암호화하는 랜섬웨어로, 본문에서는 CRAT 및 Xctdoor 초기 버전과 함께 사용된 사례가 설명된다.
A ransomware plugin used by CRAT that locks targeted files into password-protected RAR archives, encrypts the archive passwords with an embedded RSA public key, drops ransom notes, disables defenses, establishes persistence, deletes shadow copies, and can function as either extortionware or potentially destructive pseudo-ransomware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.