The operators behind Mamba ransomware resumed attacks against corporate networks, using the legitimate DiskCryptor utility to lock entire disks rather than just individual files. After gaining access to a victim environment, the attackers used PsExec to spread the malware across machines, then installed DiskCryptor components, a driver, and a malicious auto-start service before forcing a reboot.
On the next stage, Mamba modified the MBR bootloader, encrypted disk partitions, and rebooted systems again to present a ransom note. Each infected machine received a unique DiskCryptor password passed to the dropper through command-line arguments, making recovery effectively impossible without the attacker-held key because DiskCryptor relies on strong encryption. The campaign follows the group’s earlier use of the malware in the San Francisco Municipal Transportation Agency incident, underscoring the continued threat posed by disk-encrypting ransomware in enterprise environments.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
On 2021-03-23, the FBI, in coordination with DHS-CISA, issued Alert CU-000143-MW on Mamba ransomware. The alert described Mamba’s use of DiskCryptor against multiple sectors, published technical indicators and mitigations, and noted that responders may recover the encryption password from myConf.txt before the second reboot.
Mamba ransomware was used in a major 2016 attack against San Francisco’s Municipal Transportation Agency, establishing the malware’s earlier known use before the renewed activity described in the report.
The Securelist report says the threat actor behind Mamba resumed targeting corporate networks. It also disclosed technical details of the malware’s deployment, including use of PsExec and the legitimate DiskCryptor utility for full-disk encryption.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.