Cisco Talos released a free ThanatosDecryptor for victims of the Thanatos ransomware, a strain whose broken encryption routinely made files unrecoverable even after ransom payment. Researchers said Thanatos encrypted files with per-file AES-256 keys derived from a weak GetTickCount system-uptime value, then failed to preserve those keys, leaving victims unable to rely on the attackers for restoration. The malware renamed files with the .THANATOS extension, dropped a README.txt ransom note, created a Windows autorun registry entry to reopen the note at login, and in some cases contacted an iplogger.com URL to track infections.
Talos said Thanatos spread in multiple campaigns, including via Discord attachments, and that some variants appeared designed to destroy data rather than support payment and decryption. The ransom note demanded about $200 and accepted Bitcoin, Ethereum, and Bitcoin Cash, making it one of the first ransomware families reported to take Bitcoin Cash, yet observed wallet activity suggested the operator earned only about $720 in total and some listed wallets were invalid or unused. Talos open-sourced its decryptor and said recovery works best on the same machine where encryption occurred, with support limited to certain file types by narrowing the 32-bit uptime-derived key space using Windows Event Log data and file timestamps.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos released a free tool, ThanatosDecryptor, to help victims recover files encrypted by Thanatos. Talos had found a way to break the ransomware's flawed encryption routine and also open-sourced the decryptor.
Talos said Thanatos Version 1.1 was distributed mainly between February and April 2018. This version expanded payment options to Bitcoin, Ethereum, and Bitcoin Cash and instructed victims to send a MachineID to the attacker by email.
BleepingComputer reported that MalwareHunterTeam discovered the Thanatos ransomware in February 2018. The malware was notable for encrypting files with per-file keys that were not saved, making recovery by paying unlikely.
Cisco Talos reported that Thanatos Version 1 was distributed in mid-February 2018. This early version used a primitive README.txt ransom note and demanded 0.01 BTC.
Talos identified a campaign in which Thanatos was delivered as an attachment through Discord, including a sample named fastleafdecay.exe. One observed sample explicitly stated that decryption was unavailable, leading Talos to assess the campaign was intended to destroy victim data rather than collect ransom.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
blog.talosintelligence.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.