UIWIX is a Windows ransomware family known for fileless execution techniques and worm-like propagation via the EternalBlue SMB exploit. It has been associated with in-memory operation and abuse of legitimate Windows components rather than relying solely on conventional dropped executables, placing it among ransomware strains that helped popularize fileless tradecraft in 2017. UIWIX has also been noted for using layered encryption approaches to scramble victim files.
Operationally, UIWIX is documented as spreading in a manner similar to other EternalBlue-enabled ransomware outbreaks, using SMB exploitation to move to vulnerable systems on local or reachable networks. Its behavior aligns with ransomware campaigns that combine encryption with self-propagation, increasing impact inside poorly patched Windows environments. UIWIX is primarily relevant to enterprise and organizational networks exposed to unpatched SMB services, where rapid lateral spread can amplify disruption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Around November 2017, Satan devs started their plans of updating the ransomware to better fit these trends. The first step they took was to incorporate a version of the EternalBlue SMB exploit. The addition of this exploit meant that after Satan infected a computer, the ransomware would use EternalBlue to scan the local network for computers with outdated SMB services and infect them as well, maximizing an attack's impact. | Other ransomware strains that used EternalBlue included WannaCry, NotPetya, and UIWIX, and all used it in a similar way.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another ransomware family that used EternalBlue for propagation.
Referenced as another ransomware family known for layered encryption.
A fileless ransomware family mentioned as an example of fileless malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.