Snake (also known as EKANS) was used in targeted intrusions against industrial organizations, including reported victims such as Honda and Enel Group, with malware samples customized for specific environments. Analysis showed the ransomware embedded an internal domain name and expected IP address, then encrypted files only if DNS resolution matched the hard-coded value, indicating deliberate victim validation and an effort to prevent execution outside the intended network. Researchers assessed the ransomware was typically deployed as the final stage of a multistage compromise after attackers obtained privileged access, likely including compromised domain administrator credentials used to spread the payload through domain policies.
Technical analysis of a Golang-based, Gobfuscate-obfuscated sample found Snake checked the victim environment through WMI and avoided encrypting primary or backup domain controllers, instead dropping a ransom note, while using those systems to preserve propagation capability. On non-controller hosts, the malware enabled and reconfigured Windows Firewall, killed numerous security and industrial-related processes and services, deleted shadow copies, and encrypted files using per-file AES-CTR keys protected with RSA-2048 OAEP; encrypted files were marked with the string EKANS. The malware also retained behavior relevant to operational technology environments, including attempts to terminate General Electric ICS-related processes, reinforcing concerns about its impact on industrial operations.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Kaspersky ICS CERT reported targeted attacks against industrial companies using Snake/EKANS ransomware. The attacks used victim-specific samples that embedded an internal domain name and IP address to ensure encryption ran only inside the intended target network.
On June 8, 2020, Honda experienced computer network issues affecting Europe and Japan, with Honda Customer Service and Honda Financial Services reporting technical difficulties. Security experts assessed that a Honda server was likely infected with Snake ransomware, and a sample checked for Honda's domain mds.honda.com.
Dragos reported that EKANS had been traced to at least attempted intrusion or disruption involving Fresenius Group and Enel Group, expanding the publicly identified victim set beyond Honda. The report also said the known victims likely represented only a subset of total EKANS activity.
On January 8, 2020, BleepingComputer reported that MalwareHunterTeam discovered the SNAKE, or EKANS, ransomware and shared it with Vitali Kremez for analysis. The analysis described an enterprise-targeting Golang ransomware that kills ICS/SCADA-related processes, deletes Shadow Volume Copies, encrypts files across compromised business networks, and drops a Fix-Your-Files.txt ransom note.
A July 7, 2020 update added that Snake checks a system's domain role and terminates without encrypting if it is a primary or backup domain controller. Kaspersky said this supported the view that attackers kept domain controllers operational to help propagate the ransomware via domain policies.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
11 references tracked. Mallory keeps watching after this page renders.
0ffset.net
Open sourcembsd.jp
Open sourcembsd.jp
Open sourcembsd.jp
Open sourcefireeye.com
Open sourcepylos.co
Open sourcebleepingcomputer.com
Open sourcecrowdstrike.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.