Rhino ransomware, also tracked as Marvel, was identified as a business-targeting crypto-ransomware family that encrypted files using AES+RSA and demanded Bitcoin for decryption. Reporting says the malware emerged in early 2020, primarily hit English-speaking victims, and appended extensions such as .[generalchin@countermail.com].rhino to locked files. Its ransom notes were delivered through files including info.hta, Decryptor_Info.hta, and ReadMe_Decryptor.txt, while a sample later analyzed by VMRay had reportedly been found by security researcher @GrujaRS.
Technical reporting links Rhino/Marvel to the broader DCRTR ransomware lineage and says the family evolved into multiple later variants and aliases, including Parrot, Coka, and Termit, each using different extensions and contact addresses. Analysts documented behavior consistent with enterprise-focused ransomware, including stopping security and server-related services, deleting shadow copies, disabling recovery features, establishing persistence through Run registry keys, and using mutexes such as Marvel and Marvel01.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
An October 2020 variant of the Rhino/Marvel family used the extension .[ashtray@outlookpro.net].termit and contact addresses including ashtray@outlookpro.net. The activity was accompanied by the hacking tool NetTool.Scan, also called Network Scanner.
A June 2020 variant of the Rhino/Marvel family used the extension .[servicemanager@yahooweb.co].coka and multiple contact addresses including servicemanager@yahooweb.co. The variant reportedly used the file marker Marvel101.
Rhino ransomware, also referred to as Marvel, was first identified in April 2020. The family was described as active around early April 2020 and targeting business environments.
A Rhino ransomware sample analyzed by VMRay was reportedly found by Twitter user @GrujaRS on May 4th. The source does not specify the year for that date.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.