EKANS
MITRE ATT&CK: S0605 View on attack.mitre.org
Aliases: SNAKEHOSE, EKANS
- First seen
- 2019-12-15 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Last IoC activity
- 2026-07-19 02:51:01
- Profile updated
- 2026-07-07 12:58:27
Targeted industries: energy-and-utilities healthcare-and-pharmaceutical manufacturing
Context
EKANS is ransomware variant written in Golang that first appeared in mid-December 2019 and has been used against multiple sectors, including energy, healthcare, and automotive manufacturing, which in some cases resulted in significant operational disruptions. EKANS has used a hard-coded kill-list of processes, including some associated with common ICS software platforms (e.g., GE Proficy, Honeywell HMIWeb, etc), similar to those defined in MegaCortex.
Detection coverage
- 1 YARA rules
- 370 Sigma rules
Malware & tools used
- Process Discovery (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Service Stop (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Service Stop (attack-pattern)
- Network Connection Enumeration (attack-pattern)
- Loss of Productivity and Revenue (attack-pattern)
- Masquerading (attack-pattern)
Detection rules
- TRELLIX_ARC_Snake_Ransomware (yara-rule)
Reports & references
- CrowdStrike — Report2021Gtr (report)
- CrowdStrike — Adversaries Targeting The Manufacturing Industry (report)
- ics-cert.kaspersky.com — Kaspersky H1 2020 Ics Report En (report)
- ke-la.com — Zooming Into Darknet Threats Targeting Jp Orgs Kela (report)
- Mandiant — Financially Motivated Actors Are Expanding Access Into Ot (report)
- Mandiant — Financially Motivated Actors Are Expanding Access Into Ot (report)
- blackberry.com — Report Old Dogs New Tricks (report)
- hub.dragos.com — Dragos Manufacturing%20Threat%20Perspective 1120 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Snake (report)
- ics-cert.kaspersky.com — Targeted Attacks On Industrial Companies Using Snake Ransomware (report)
- medium.com — Malware Analysis Snake Ransomware A0E66F487017 (report)
- labs.sentinelone.com — New Snake Ransomware Adds Itself To The Increasing Collection Of Golang Crimeware (report)
- bleepingcomputer.com — Snake Ransomware Is The Next Threat Targeting Business Networks (report)
- dragos.com — Ekans Ransomware Misconceptions And Misunderstandings (report)
- insights.sei.cmu.edu — Snake Ransomware Analysis Updates (report)
- dragos.com — Ekans Ransomware And Ics Operations (report)
- blog.malwarebytes.com — Honda And Enel Impacted By Cyber Attack Suspected To Be Ransomware (report)
- twitter.com — 1270957214300135426 (report)
- ccn-cert.cni.es — File (report)
- krebsonsecurity.com — Europes Largest Private Hospital Operator Fresenius Hit By Ransomware (report)
- github.com — Snake.Md (report)
- twitter.com — 1270019326976786432 (report)
- fortinet.com — Ekans Ransomware Targeting Ot Ics Systems (report)
- 0ffset.net — Analysing Snake Ransomware (report)
- goggleheadedhacker.com — 22 (report)