FortiGuard Labs said the DeathRansom ransomware campaign is strongly tied to Vidar stealer activity and several other malware operations through shared infrastructure, naming conventions, and recurring attribution artifacts. Researchers found Vidar samples attempting to access Bitbucket paths under the profile name scat01 and likely retrieving DeathRansom variants named in the Wacatac_YYYY-MM-DD_HH-MM.exe format. The same cluster was also linked to Azorult, Evrial stealer, 1ms0rryStealer, and Supreme miner, with repeated use of identifiers including the nickname scat01, the email vitasa01@yandex.ru, and the domain gameshack[.]ru. FortiGuard assessed that false Slovak and Nepali language artifacts were likely planted to mislead investigators, while other evidence pointed to a Russian-speaking operator associated with the online persona SoftEgorka and likely connected to Egor Nedugov from the Rostov-on-Don/Aksay area.
Separate technical profiling described DeathRansom, also detected in some cases as Wacatac, as a ransomware family that evolved from early variants that sometimes only mimicked encryption into later builds that performed real file encryption. The malware primarily targeted English-speaking users, dropped a read_me.txt ransom note, demanded Bitcoin payment through attacker-controlled email addresses, and checked systems against a whitelist of CIS-region languages before running. Analysts documented multiple delivery paths, including RDP compromise, spam, malicious downloads, botnets, exploits, malvertising, fake updates, and trojanized installers, and noted changing cryptographic implementations involving Curve25519/ECDH, Salsa20, RSA-2048, AES, and SHA-256. The reporting also noted code or family relationships with EZDZ-Locker, TechandStrat, HelloKitty, FiveHands, DCRTR, and STOP ransomware.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
AhnLab ASEC reported discovering the DEATHRansom ransomware family being distributed in South Korea on November 20, 2019. The report said the malware encrypted files without changing extensions, dropped read_me.txt ransom notes, and was detected by AhnLab V3 with file- and behavior-based signatures.
The ID Ransomware profile lists Wacatac_2019-11-20_23-34.exe among associated DeathRansom filenames, documenting another dated sample from the campaign.
FortiGuard cited a DeathRansom-related sample named Wacatac_2019-11-20_00-10.exe as part of the campaign's naming pattern and infrastructure overlap with Vidar.
An update dated 20 November 2019 states that DeathRansom variants were then actually encrypting files rather than merely pretending to, using Curve25519 ECDH, Salsa20, RSA-2048, AES-256 ECB, and XOR without adding an extension.
Researchers documented a DeathRansom-related sample using the filename Wacatac_2019-11-20_00-10.exe, including a distribution URL on webparroquia.es for that file.
A Vidar sample attempted to access an inaccessible file named Wacatac_2019-11-16_17-03.exe, which FortiGuard assessed was likely another DeathRansom variant.
FortiGuard identified a Bitbucket download path under the scat01 profile for a file named Wacatac_2019-11-16_14-06.exe, which researchers associated with the DeathRansom campaign.
The ID Ransomware profile places notable DeathRansom activity in mid-November 2019, describing early variants that used the DEATHRANSOM ransom note branding and in some cases only pretended to encrypt files while appending the .wctc extension.
FortiGuard found a connections log from May 2019 showing a Vidar stealer sample referencing the Bitbucket directory used under the profile name "scat01," an early infrastructure link later tied to DeathRansom activity.
FortiGuard Labs published research concluding that DeathRansom was strongly linked to Vidar stealer and other malware operations through shared infrastructure, naming conventions, and attribution artifacts, and tied the activity to the personas scat01 and SoftEgorka.
The ID Ransomware profile lists Wacatac_2019-11-21_02-59.exe as an associated filename, showing continued dated sample generation in the DeathRansom campaign.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 34 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
fortinet.com
Open sourceasec.ahnlab.com
Open sourceid-ransomware.blogspot.com
Open sourcevirustotal.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.