Entropy is a Windows ransomware family observed in targeted intrusions where operators conducted network access, lateral movement, reconnaissance, and data theft before attempting encryption. It has been deployed as a 32-bit DLL and executed through regsvr32 via DllRegisterServer, with victim-specific builds containing hardcoded references to the targeted organization and customized ransom-note content. Reported incidents show operators staging the payload across multiple hosts with administrative tooling and scripts after establishing broad access in the victim environment.
Observed Entropy attacks were preceded by use of remote-access and post-compromise tooling including Cobalt Strike and Dridex, with one intrusion involving exploitation of Microsoft Exchange ProxyShell and another beginning from a malicious email attachment that delivered Dridex. In these cases, attackers used dual-use tools for reconnaissance, lateral movement, staging, and execution, and compressed and exfiltrated data to cloud storage before ransomware deployment, indicating a double-extortion style workflow.
Reverse-engineering has identified notable similarities between Entropy and Dridex in packer behavior and anti-analysis logic, including vectored exception handler setup, string decoding, and API resolution routines. These overlaps suggest a possible tooling or development relationship, though public reporting has treated the linkage as suggestive rather than conclusive. Entropy has also been discussed in the context of ransomware activity potentially associated with Evil Corp due to these code and operational overlaps, but attribution remains cautious. Confirmed victim sectors include media and regional government organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In the first incident, the attackers exploited the ProxyShell vulnerability on the network belonging to a North American media organization, to install a remote shell on the target’s Exchange server, and leveraged that to spread Cobalt Strike beacons to other computers. | A pair of incidents at different organizations in which attackers deployed a ransomware called Entropy were preceded by infections with tools that provided the attackers with remote access — Cobalt Strike beacons and Dridex malware — on some of the targets’ computers, before the attackers launched the ransomware.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A pair of incidents at different organizations in which attackers deployed a ransomware called Entropy were preceded by infections with tools that provided the attackers with remote access — Cobalt Strike beacons and Dridex malware — on some of the targets’ computers, before the attackers launched the ransomware.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The packer code used to protect the Entropy ransomware ... some of the other subroutines the ransomware uses to obfuscate its behavior
The Entropy samples in both cases were delivered in the form of Windows DLL files ... Attackers executed it using a command line ... regsvr32 c:\users\public\xyz.dll DllRegisterServer <20 random characters>
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware delivered as a Windows DLL, customized per victim organization, executed via regsvr32 with a required password-like parameter. It encrypts victim systems after attackers conduct reconnaissance and data exfiltration, and it uses obfuscation, packer code, API resolution, and string decryption routines that researchers found similar to Dridex.
Ransomware whose code resembles Dridex and that was delivered in attacks by Dridex bots.
Entropy is a ransomware family delivered as a Windows DLL that encrypts victim systems and drops a customized HTML ransom note. In the described incidents, operators used it after initial access and lateral movement, with custom builds hardcoded for each victim organization and execution via regsvr32 with a required password-like parameter.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.