Satana is a Windows ransomware family first observed in 2016 that combines file encryption with destructive boot-disk tampering. It is notable for overwriting the Master Boot Record and encrypting files on the victim system, blending behaviors associated with both ransomware and bootlocker-style malware. Analyses of related ransomware families have highlighted Satana’s use of direct physical-drive access for MBR modification and a normal reboot mechanism to activate its boot-stage effects.
Satana has been discussed in comparative research on MBR-targeting ransomware because its implementation differs from Petya-derived families in several key areas, including how it accesses the system drive and how it triggers reboot. It has also been cited as an example of ransomware using file-mapping APIs for in-place file encryption, an uncommon implementation detail later echoed by other malware.
Genealogical analysis has linked Satana to the later CoronaVirus ransomware family. In that lineage, CoronaVirus retained the combination of MBR modification and file encryption while adding boot-time lock-screen behavior and serving as cover for deployment of the Kpot information stealer. This relationship indicates Satana’s influence on subsequent ransomware that combined extortion with broader post-compromise monetization.
Satana targets Windows systems and is primarily characterized as ransomware due to its encryption and boot disruption behavior. High-confidence reporting supports destructive modification of boot structures, encryption of victim files, and reboot-driven activation of its ransom functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MBR書き換え型ランサムウェア。"\\.\PHYSICALDRIVE0" を固定指定し、SetFilePointerで先頭位置を決め打ちしてMBRへ書き込む。NotPetyaとは一部類似点があるが、ブート領域書き換えデータは大きく異なる。
MBR書き換えとファイル暗号化を行うランサムウェア。今回の検体と同様にファイルマッピングを利用した暗号化手法を採る比較対象として挙げられている。
Referenced as an ancestral/related ransomware family in the genealogy of CoronaVirus, indicating code or family relationship rather than being the main subject of the article.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.