ATANK
- First seen
- 2018-01-01 00:00:00
- Malware type
- ransomware, wiper
- Last IoC activity
- 2026-06-04 15:58:48
- Profile updated
- 2026-07-07 14:04:14
Context
According to Lukas Stefanko, this is an open-source crypto-ransomware found on Github in 2018. IT can en/decrypt files (AES, key: 32 random chars, sent to C&C), uses email as contact point but will remove all files after 24 hours or after a reboot.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Atank (report)
- twitter.com — 1268070798293708800 (report)