CISA published a Malware Analysis Report on a successful intrusion that deployed FiveHands ransomware after attackers used the SombRAT remote access trojan and a collection of legitimate administrative and open-source tools. The report analyzed 18 malicious files and identified a new FiveHands variant alongside multiple SombRAT loader and payload components disguised as WwanSvc files, showing a multi-stage attack that moved from initial access to reconnaissance, lateral movement, and encryption.
The artifacts showed attackers conducting network discovery with SoftPerfect Network Scanner, using PsExec for remote execution, applying a PowerShell-based AMSI bypass and in-memory loading techniques, then deleting shadow copies and dropping ransom notes after encrypting files. CISA also released indicators tied to the activity, including the domain feticost.com and IP address 51.89.50.152, to help defenders identify related compromise.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
The FBI issued a TLP:WHITE notice detailing tactics, techniques, and indicators associated with Hello Kitty/FiveHands ransomware, including double extortion, possible DDoS pressure, and exploitation of SonicWall vulnerabilities for initial access. The notice also shared malware/tool hashes and mitigation guidance, and said the FBI had first observed the ransomware in January 2021.
On 2021-05-06, CISA published Malware Analysis Report MAR-10324784-1.v1 after analyzing 18 malicious files tied to a recent successful cyberattack. The report identified a new ransomware variant named FiveHands, SombRAT-related components, legitimate tools used in the intrusion, and indicators including feticost.com and 51.89.50.152.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 111 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.