Spook is a Windows ransomware family first observed in late 2021 and widely assessed as a Thanos-derived variant with notable code and operational overlap with Prometheus. It is associated with double-extortion activity, combining file encryption with threats to leak stolen data and, in some reporting, threats of data destruction. Public victim-posting infrastructure and negotiation portals were part of its operating model, and manufacturing organizations appeared prominently among observed victims, although multiple industries were affected.
Spook was developed using the leaked Thanos builder, which complicates attribution because code similarities may reflect shared tooling rather than a single operator. Technical analysis has nevertheless identified substantial overlap with Prometheus in ransom-note generation, key identifier logic, and payment-portal design. The malware is implemented in .NET and can encrypt systems without requiring active internet connectivity. It uses symmetric encryption for victim data and protects the generated encryption key material with an attacker-controlled public key, making recovery without the corresponding private key impractical.
Operationally, Spook enumerates local files, folders, and accessible network resources prior to encryption. It attempts to maximize encryption success by terminating processes and stopping services that could lock files or interfere with execution, including database, office, mail, backup, and security-related components. It has also been observed specifically targeting the Raccine anti-ransomware tool for disablement and removal. Persistence and victim notification are reinforced through multiple mechanisms, including ransom-note display on the desktop, startup-based relaunch of the note, and modification of Windows logon notice settings so ransom messaging appears at login.
Spook is part of the broader ecosystem of post-leak Thanos-derived ransomware variants that adopted builder-based customization, aggressive defense evasion, and leak-site-backed extortion. Its behavior aligns with enterprise-impacting ransomware operations focused on rapid encryption, disruption of recovery and protective tooling, and coercive monetization through negotiation portals and public exposure of victim data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
WinLogon is modified (via registry) to display the Ransom Note text upon login ... HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon Str Value: LegalNoticeCaption/Text
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in passing as an example of a ransomware group/tool relationship from prior investigations.
Ransomware that encrypts files and disks using AES, can operate offline, displays ransom notes via HTA/startup/Winlogon persistence, terminates processes and disables services that may hinder encryption, and extorts victims through a TOR-based payment portal while threatening public data leakage.
A Thanos-derived ransomware variant that encrypts files, appends a .{ID} extension, drops RESTORE_FILES_INFO ransom notes, and uses double extortion via its own leak site.
A ransomware family mentioned as part of the broader lineage descending from the same builder ecosystem as Hakbit/Thanos.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.