DEATHRANSOM
MITRE ATT&CK: S0616 View on attack.mitre.org
Aliases: deathransom, wacatac, DEATHRANSOM
- First seen
- 2020-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1411 (960 malicious)
- Last IoC activity
- 2026-09-02 04:26:00
- Profile updated
- 2026-07-07 13:47:33
Targeted industries: financial-services healthcare-and-pharmaceutical professional-services technology-and-telecommunications
Context
DEATHRANSOM is ransomware written in C that has been used since at least 2020, and has potential overlap with FIVEHANDS and HELLOKITTY.
Recent IoC activity
961 malicious indicators in Maltiverse are attributed to DEATHRANSOM (S0616). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | grupoprovialsa.com | 2026-09-03 | 1 |
| hostname | r2.e-z.host | 2026-09-03 | 3 |
| hostname | ahkscript.org | 2026-09-03 | 1 |
| hostname | fatename.com | 2026-09-03 | 1 |
| hostname | mamadona.ru | 2026-09-03 | 1 |
| hostname | creationstationdance.com | 2026-09-03 | 2 |
| hostname | bibliopolis.be | 2026-09-03 | 1 |
| hostname | denki-shonan.com | 2026-09-03 | 1 |
| hostname | willtorock.com | 2026-09-03 | 1 |
| hostname | fsgpj.com | 2026-09-02 | 1 |
| hostname | acvconsultoria.com | 2026-09-02 | 2 |
| hostname | tecnohumanismo.online | 2026-09-02 | 1 |
| hostname | dl.loudplay.ru | 2026-09-02 | 2 |
| hostname | browserss.ru | 2026-09-02 | 1 |
| hostname | gtagamer.org | 2026-09-02 | 1 |
| hostname | ttriber.com | 2026-09-02 | 1 |
| hostname | www.vxdiag.net | 2026-09-02 | 2 |
| hostname | d.zaix.ru | 2026-09-02 | 4 |
| hostname | static.s123-cdn.com | 2026-09-02 | 3 |
| hostname | mscmotocross.com | 2026-09-02 | 1 |
Detection coverage
- 2 YARA rules
- 209 Sigma rules
Malware & tools used
- Data Encrypted for Impact (attack-pattern)
- Web Protocols (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- System Language Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Network Share Discovery (attack-pattern)
Detection rules
- DITEKSHEN_MALWARE_Win_Deathransom (yara-rule)
- MALPEDIA_Win_Deathransom_Auto (yara-rule)
Reports & references
- ransomlook.io — Deathransom (report)
- Trend Micro — Deathransom Now Fully Operational With File Encryption Capabilities (report)
- bleepingcomputer.com — Deathransom Ransomware Now Encrypting Victims Data (report)
- pcrisk.com — 16697 Deathransom Ransomware (report)
- Mandiant — Unc2447 Sombrat And Fivehands Ransomware Sophisticated Financial Threat (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Deathransom (report)
- fortinet.com — Death Ransom New Strain Ransomware (report)
- asec.ahnlab.com — 1269 (report)
- blog.cyber5w.com — The Most Known Unpacking Technique (report)
- dissectingmalwa.re — Quick And Painless Reversing Deathransom Wacatac (report)
- github.com — Deathransom.Md (report)
- fortinet.com — Death Ransom Attribution (report)
- id-ransomware.blogspot.com — Wacatac Ransomware (report)
- twitter.com — 1196898012645220354 (report)
- MITRE ATT&CK — S0616 (report)