Atomsilo
- First seen
- 2021-09-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-07 03:22:01
- Profile updated
- 2026-07-07 12:55:00
Targeted industries: technology-and-telecommunications government-and-public-sector healthcare-and-pharmaceutical
Context
AtomSilo is a new Ransomware recently seen in September 2021 during one of their attacks by exploiting a recently revealed vulnerability (CVE-2021-26084) in Atlassian’s Confluence Collaboration Software for initial access. The Ransomware used the double extortion method which is gaining popularity among ransomware threat actors where they first, exfiltrate the confidential information and as a second step encrypt the system files.
Detection coverage
- 1 YARA rules
Exploited vulnerabilities
- CVE-2021-26084 (vulnerability)
Detection rules
- MALPEDIA_Win_Atomsilo_Auto (yara-rule)
Reports & references
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- secureworks.com — Bronze Starlight Ransomware Operations Use Hui Loader (report)
- news.sophos.com — The Ransomware Threat Intelligence Center (report)
- cyfirma.com — Malware Research On Atomsilo Ransomware (report)
- zscaler.com — Atomsilo Ransomware Enters League Double Extortion (report)
- twitter.com — 1437664046556274694 (report)
- news.sophos.com — Atom Silo Ransomware Actors Use Confluence Exploit Dll Side Load For Stealthy Attack (report)
- chuongdong.com — Atomsiloransomware (report)
- decoded.avast.io — Decryptor For Atomsilo And Lockfile Ransomware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Atomsilo (report)
- chuongdong.com — Atomsiloransomware (report)
- twitter.com — 1437664046556274694 (report)
- ransomlook.io — Atomsilo (report)