Bandarchor

Aliases: Rakhni, Agent.iih, Aura, Autoit, Pletor, Rotor, Lamer, Isda, Cryptokluchen, Bandarchor

First seen
2013-07-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-22 01:55:25
Profile updated
2026-07-07 15:43:01

Targeted regions: country_code:ru country_code:ua

Context

Bandarchor, also known as Rakhni, is a ransomware family that partially encrypts files, demanding a ransom from victims to restore access. It has been known to target various regions, notably in Russia and Ukraine.

Detection coverage

  • 3 YARA rules

Detection rules

  • RUSSIANPANDA_Darkgate_Autoit (yara-rule)
  • DITEKSHEN_MALWARE_Win_Redlinedropperahk (yara-rule)
  • DITEKSHEN_MALWARE_Win_Quilclipper (yara-rule)

Reports & references

  • reaqta.com — Bandarchor Ransomware Still Active (report)
  • bleepingcomputer.com — New Bandarchor Ransomware Variant Spreads Via Malvertising On Adult Sites (report)
  • support.kaspersky.com — 10556 (report)
  • id-ransomware.blogspot.com — Bandarchor Ransomware Aes 256 (report)

External references