Researchers identified a new .NET ransomware family, HavanaCrypt, that disguises itself as a Google Software Update application while communicating with command-and-control infrastructure at 20[.]227[.]128[.]33, an IP address described as part of a Microsoft web hosting service. The malware is protected with Obfuscar, performs multiple anti-virtualization checks, fingerprints infected systems, and contacts ham.php and index.php to retrieve a token, date, and encryption-related material before launching file encryption.
HavanaCrypt weakens defenses by downloading a batch file to reduce Windows Defender protections, kills numerous processes, deletes shadow copies and restore points, and persists by copying itself into startup-related directories. During encryption it uses components associated with KeePass Password Safe, including CryptoRandom, stores an RSA key in hava.info, records encrypted directories in foo.txt, and appends the .Havana extension to locked files. Researchers noted that the malware did not drop a ransom note, indicating the ransomware may still have been under development at the time of analysis.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Trend Micro researchers published an analysis of a new ransomware family they named HavanaCrypt, describing its masquerade as a Google Software Update application, its Microsoft-hosted C2 infrastructure, and its encryption behavior. The report noted the malware did not drop a ransom note, suggesting it may still have been under development at the time of analysis.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.