A newly identified Erebus ransomware sample was found using a Windows User Account Control bypass to gain elevated execution without prompting the victim. The malware abuses eventvwr.exe by hijacking the .msc file association in the registry, a technique publicly documented as a fileless UAC bypass, then proceeds to collect the victim's IP address and country information, download a Tor client, and connect to an onion-based payment and command infrastructure.
Once active, Erebus encrypts a wide range of document and image files with AES, renames affected files using ROT-23, and deletes Windows Volume Shadow Copies to make recovery harder. It drops README.html ransom notes on the Desktop and in Documents, displays an on-screen message, and demands 0.085 BTC—about $90—within 96 hours; at the time of reporting, no free decryption option was available for victims of this sample.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Analysis of the sample showed it hijacked the .msc file association in the registry and launched via eventvwr.exe to execute with elevated privileges without a UAC prompt. The ransomware then encrypted files with AES, deleted Volume Shadow Copies, dropped README.html ransom notes, and demanded 0.085 bitcoins with a 96-hour deadline.
MalwareHunterTeam discovered a potentially new ransomware sample named Erebus on VirusTotal. Analysis indicated it was likely a rewrite or a different ransomware family reusing the Erebus name from an earlier 2016 report.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.