The Satan ransomware operation, originally launched as a ransomware-as-a-service platform, evolved from affiliate-delivered file encryption into a network-spreading threat that abused multiple enterprise attack paths. Early versions let affiliates generate customized payloads, distribute them through droppers such as malicious Word macros or CHM installers, and encrypt files with extensions such as .stn while directing victims to Tor-based payment portals.
Later variants added worm-like and post-exploitation capabilities, including EternalBlue SMB exploitation, DoublePulsar-style propagation, and eventually Mimikatz credential dumping for lateral movement. Researchers reported infections beginning with a downloader such as sts.exe, which fetched password-protected archives containing the encryptor and propagation tools, dropped payloads such as C:\Cryptor.exe, killed database-related processes, and spread across vulnerable networks. The rebranded DBGer strain also incorporated exploitation of JBoss CVE-2017-12149, WebLogic CVE-2017-10271, and Tomcat brute forcing, appended .dbger-style encrypted filenames, and dropped _How_to_decrypt_files.txt ransom notes demanding up to 1 bitcoin.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
At the start of May 2018, researchers observed new Satan versions attempting lateral movement and infection through JBoss CVE-2017-12149, WebLogic CVE-2017-10271, and Tomcat brute forcing. These additions expanded Satan beyond SMB-based propagation.
A Satan downloader sample named sts.exe associated with the newer propagation-capable variant was compiled. The sample later retrieved password-protected archives containing the ransomware payload and EternalBlue propagation tooling.
Around November 2017, Satan developers updated the ransomware to spread across local networks using the EternalBlue SMB exploit. This marked a shift from basic affiliate-distributed ransomware toward self-propagating network infections.
A new ransomware-as-a-service platform named Satan was discovered, allowing affiliates to register, generate customized ransomware builds, and rely on the operator to handle ransom payments and feature development. Early Satan samples encrypted files with the .stn extension and dropped HELP_DECRYPT_FILES.html ransom notes.
Researchers reported that Satan’s operators had rebranded the malware as DBGer ransomware. Intezer linked DBGer to Satan through code similarity analysis, and the new variant used Mimikatz to dump credentials for lateral movement across networks.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcebartblaze.blogspot.com
Open sourcebleepingcomputer.com
Open sourcealienvault.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.