Atomsilo

First seen
2021-09-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-07 03:22:01
Profile updated
2026-07-07 12:55:00

Targeted industries: technology-and-telecommunications government-and-public-sector healthcare-and-pharmaceutical

Context

AtomSilo is a new Ransomware recently seen in September 2021 during one of their attacks by exploiting a recently revealed vulnerability (CVE-2021-26084) in Atlassian’s Confluence Collaboration Software for initial access. The Ransomware used the double extortion method which is gaining popularity among ransomware threat actors where they first, exfiltrate the confidential information and as a second step encrypt the system files.

Detection coverage

  • 1 YARA rules

Exploited vulnerabilities

  • CVE-2021-26084 (vulnerability)

Detection rules

  • MALPEDIA_Win_Atomsilo_Auto (yara-rule)

Reports & references

  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • secureworks.com — Bronze Starlight Ransomware Operations Use Hui Loader (report)
  • news.sophos.com — The Ransomware Threat Intelligence Center (report)
  • cyfirma.com — Malware Research On Atomsilo Ransomware (report)
  • zscaler.com — Atomsilo Ransomware Enters League Double Extortion (report)
  • twitter.com — 1437664046556274694 (report)
  • news.sophos.com — Atom Silo Ransomware Actors Use Confluence Exploit Dll Side Load For Stealthy Attack (report)
  • chuongdong.com — Atomsiloransomware (report)
  • decoded.avast.io — Decryptor For Atomsilo And Lockfile Ransomware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Atomsilo (report)
  • chuongdong.com — Atomsiloransomware (report)
  • twitter.com — 1437664046556274694 (report)
  • ransomlook.io — Atomsilo (report)

External references