FIVEHANDS
MITRE ATT&CK: S0618 View on attack.mitre.org
Aliases: Thieflock, FIVEHANDS
- First seen
- 2021-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:02:54
Targeted industries: healthcare-and-pharmaceutical financial-services government-and-public-sector energy-and-utilities
Targeted regions: country_code:us country_code:ca country_code:uk
Context
FIVEHANDS is a customized version of DEATHRANSOM ransomware written in C++. FIVEHANDS has been used since at least 2021, including in Ransomware-as-a-Service (RaaS) campaigns, sometimes along with SombRAT.
Detection coverage
- 1 YARA rules
- 194 Sigma rules
Malware & tools used
- Windows Management Instrumentation (attack-pattern)
- Command and Scripting Interpreter (attack-pattern)
- Network Share Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
Detection rules
- DITEKSHEN_MALWARE_Win_Kitty (yara-rule)
Reports & references
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- esentire.com — Hacker Infrastructure Used In Cisco Breach Discovered Attacking A Top Workforce Management Corporation Russias Evil Corp Gang Suspected Reports Esentire (report)
- rewterz.com — Rewterz Threat Alert Financially Motivated Aggressive Group Carrying Out Ransomware Campaigns Active Iocs (report)
- Broadcom/Symantec — The Ransomware Threat September 2021 (report)
- esentire.com — Conti Affiliate Exposed New Domain Names Ip Addresses And Email Addresses Uncovered By Esentire (report)
- CISA — Aa22 249A (report)
- CrowdStrike — New Ransomware Variant Uses Golang Packer (report)
- Mandiant — Unc2447 Sombrat And Fivehands Ransomware Sophisticated Financial Threat (report)
- Broadcom/Symantec — Yanluowang Ransomware Attacks Continue (report)
- Mandiant — Darkside Affiliate Supply Chain Software Compromise (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Fivehands (report)
- research.nccgroup.com — Handy Guide To A New Fivehands Ransomware Variant (report)
- CISA — Ar21 126A (report)
- CISA — Ar21 126B (report)
- bleepingcomputer.com — Yanluowang Ransomware Operation Matures With Experienced Affiliates (report)
- MITRE ATT&CK — S0618 (report)