FIVEHANDS

MITRE ATT&CK: S0618 View on attack.mitre.org

Aliases: Thieflock, FIVEHANDS

First seen
2021-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:02:54

Targeted industries: healthcare-and-pharmaceutical financial-services government-and-public-sector energy-and-utilities

Targeted regions: country_code:us country_code:ca country_code:uk

Context

FIVEHANDS is a customized version of DEATHRANSOM ransomware written in C++. FIVEHANDS has been used since at least 2021, including in Ransomware-as-a-Service (RaaS) campaigns, sometimes along with SombRAT.

Detection coverage

  • 1 YARA rules
  • 194 Sigma rules

Malware & tools used

  • Windows Management Instrumentation (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)

Detection rules

  • DITEKSHEN_MALWARE_Win_Kitty (yara-rule)

Reports & references

  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • esentire.com — Hacker Infrastructure Used In Cisco Breach Discovered Attacking A Top Workforce Management Corporation Russias Evil Corp Gang Suspected Reports Esentire (report)
  • rewterz.com — Rewterz Threat Alert Financially Motivated Aggressive Group Carrying Out Ransomware Campaigns Active Iocs (report)
  • Broadcom/Symantec — The Ransomware Threat September 2021 (report)
  • esentire.com — Conti Affiliate Exposed New Domain Names Ip Addresses And Email Addresses Uncovered By Esentire (report)
  • CISA — Aa22 249A (report)
  • CrowdStrike — New Ransomware Variant Uses Golang Packer (report)
  • Mandiant — Unc2447 Sombrat And Fivehands Ransomware Sophisticated Financial Threat (report)
  • Broadcom/Symantec — Yanluowang Ransomware Attacks Continue (report)
  • Mandiant — Darkside Affiliate Supply Chain Software Compromise (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Fivehands (report)
  • research.nccgroup.com — Handy Guide To A New Fivehands Ransomware Variant (report)
  • CISA — Ar21 126A (report)
  • CISA — Ar21 126B (report)
  • bleepingcomputer.com — Yanluowang Ransomware Operation Matures With Experienced Affiliates (report)
  • MITRE ATT&CK — S0618 (report)

External references