Researchers identified Anatova as a new ransomware family with a modular architecture that could expand beyond file encryption into additional malicious functions such as data theft or backdoor deployment. McAfee reported finding the malware distributed through private peer-to-peer networks, where it was disguised as games or applications to lure victims, and said infections were observed globally, with notable activity in the United States and parts of Europe.
Once executed, Anatova seeks administrator privileges, encrypts files using Salsa20, targets network shares, and deletes Windows Volume Shadow Copies to hinder recovery. The malware also uses anti-analysis techniques including checks for usernames associated with sandbox or analyst environments, encrypted strings, and dynamic API calls, while demanding a ransom payment of 10 DASH from victims.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Anatova was first observed in January 2019 after McAfee researchers discovered it in a private peer-to-peer network, where it masqueraded as a game or application to lure victims into downloading it.
The analyzed Anatova sample carried a compilation date of January 1, 2019, providing the earliest explicit anchor for the malware's development timeline.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.