EKANS

MITRE ATT&CK: S0605 View on attack.mitre.org

Aliases: SNAKEHOSE, EKANS

First seen
2019-12-15 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Last IoC activity
2026-07-19 02:51:01
Profile updated
2026-07-07 12:58:27

Targeted industries: energy-and-utilities healthcare-and-pharmaceutical manufacturing

Context

EKANS is ransomware variant written in Golang that first appeared in mid-December 2019 and has been used against multiple sectors, including energy, healthcare, and automotive manufacturing, which in some cases resulted in significant operational disruptions. EKANS has used a hard-coded kill-list of processes, including some associated with common ICS software platforms (e.g., GE Proficy, Honeywell HMIWeb, etc), similar to those defined in MegaCortex.

Detection coverage

  • 1 YARA rules
  • 370 Sigma rules

Malware & tools used

  • Process Discovery (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Service Stop (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Service Stop (attack-pattern)
  • Network Connection Enumeration (attack-pattern)
  • Loss of Productivity and Revenue (attack-pattern)
  • Masquerading (attack-pattern)

Detection rules

  • TRELLIX_ARC_Snake_Ransomware (yara-rule)

Reports & references

  • CrowdStrike — Report2021Gtr (report)
  • CrowdStrike — Adversaries Targeting The Manufacturing Industry (report)
  • ics-cert.kaspersky.com — Kaspersky H1 2020 Ics Report En (report)
  • ke-la.com — Zooming Into Darknet Threats Targeting Jp Orgs Kela (report)
  • Mandiant — Financially Motivated Actors Are Expanding Access Into Ot (report)
  • Mandiant — Financially Motivated Actors Are Expanding Access Into Ot (report)
  • blackberry.com — Report Old Dogs New Tricks (report)
  • hub.dragos.com — Dragos Manufacturing%20Threat%20Perspective 1120 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Snake (report)
  • ics-cert.kaspersky.com — Targeted Attacks On Industrial Companies Using Snake Ransomware (report)
  • medium.com — Malware Analysis Snake Ransomware A0E66F487017 (report)
  • labs.sentinelone.com — New Snake Ransomware Adds Itself To The Increasing Collection Of Golang Crimeware (report)
  • bleepingcomputer.com — Snake Ransomware Is The Next Threat Targeting Business Networks (report)
  • dragos.com — Ekans Ransomware Misconceptions And Misunderstandings (report)
  • insights.sei.cmu.edu — Snake Ransomware Analysis Updates (report)
  • dragos.com — Ekans Ransomware And Ics Operations (report)
  • blog.malwarebytes.com — Honda And Enel Impacted By Cyber Attack Suspected To Be Ransomware (report)
  • twitter.com — 1270957214300135426 (report)
  • ccn-cert.cni.es — File (report)
  • krebsonsecurity.com — Europes Largest Private Hospital Operator Fresenius Hit By Ransomware (report)
  • github.com — Snake.Md (report)
  • twitter.com — 1270019326976786432 (report)
  • fortinet.com — Ekans Ransomware Targeting Ot Ics Systems (report)
  • 0ffset.net — Analysing Snake Ransomware (report)
  • goggleheadedhacker.com — 22 (report)

External references