DEATHRANSOM

MITRE ATT&CK: S0616 View on attack.mitre.org

Aliases: deathransom, wacatac, DEATHRANSOM

First seen
2020-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Related IoCs
1411 (960 malicious)
Last IoC activity
2026-09-02 04:26:00
Profile updated
2026-07-07 13:47:33

Targeted industries: financial-services healthcare-and-pharmaceutical professional-services technology-and-telecommunications

Context

DEATHRANSOM is ransomware written in C that has been used since at least 2020, and has potential overlap with FIVEHANDS and HELLOKITTY.

Recent IoC activity

961 malicious indicators in Maltiverse are attributed to DEATHRANSOM (S0616). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname grupoprovialsa.com 2026-09-03 1
hostname r2.e-z.host 2026-09-03 3
hostname ahkscript.org 2026-09-03 1
hostname fatename.com 2026-09-03 1
hostname mamadona.ru 2026-09-03 1
hostname creationstationdance.com 2026-09-03 2
hostname bibliopolis.be 2026-09-03 1
hostname denki-shonan.com 2026-09-03 1
hostname willtorock.com 2026-09-03 1
hostname fsgpj.com 2026-09-02 1
hostname acvconsultoria.com 2026-09-02 2
hostname tecnohumanismo.online 2026-09-02 1
hostname dl.loudplay.ru 2026-09-02 2
hostname browserss.ru 2026-09-02 1
hostname gtagamer.org 2026-09-02 1
hostname ttriber.com 2026-09-02 1
hostname www.vxdiag.net 2026-09-02 2
hostname d.zaix.ru 2026-09-02 4
hostname static.s123-cdn.com 2026-09-02 3
hostname mscmotocross.com 2026-09-02 1

Detection coverage

  • 2 YARA rules
  • 209 Sigma rules

Malware & tools used

  • Data Encrypted for Impact (attack-pattern)
  • Web Protocols (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • System Language Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • Network Share Discovery (attack-pattern)

Detection rules

  • DITEKSHEN_MALWARE_Win_Deathransom (yara-rule)
  • MALPEDIA_Win_Deathransom_Auto (yara-rule)

Reports & references

  • ransomlook.io — Deathransom (report)
  • Trend Micro — Deathransom Now Fully Operational With File Encryption Capabilities (report)
  • bleepingcomputer.com — Deathransom Ransomware Now Encrypting Victims Data (report)
  • pcrisk.com — 16697 Deathransom Ransomware (report)
  • Mandiant — Unc2447 Sombrat And Fivehands Ransomware Sophisticated Financial Threat (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Deathransom (report)
  • fortinet.com — Death Ransom New Strain Ransomware (report)
  • asec.ahnlab.com — 1269 (report)
  • blog.cyber5w.com — The Most Known Unpacking Technique (report)
  • dissectingmalwa.re — Quick And Painless Reversing Deathransom Wacatac (report)
  • github.com — Deathransom.Md (report)
  • fortinet.com — Death Ransom Attribution (report)
  • id-ransomware.blogspot.com — Wacatac Ransomware (report)
  • twitter.com — 1196898012645220354 (report)
  • MITRE ATT&CK — S0616 (report)

External references