EKANS
Aliases: SNAKEHOSE
- Family
- Malware family
- Operating systems
- windows
- Last IoC activity
- 2026-07-22 01:29:31
- Profile updated
- 2026-07-07 11:27:56
Context
EKANS is ransomware that was first seen December 2019 and later reported to have impacted operations at Honda automotive production facilities. EKANS has a hard-coded kill-list of processes, including some associated with common ICS software platforms (e.g., GE Proficy historian, Honeywell HMIWeb). If the malware discovers these processes on the target system, it will stop, encrypt, and rename the process to prevent the program from restarting. This malware should not be confused with the “Snake” malware associated with the Turla group. The ICS processes documented within the malware’s kill-list is similar to those defined by the MEGACORTEX software.The ransomware was initially reported as “Snake”, however, to avoid confusion with the unrelated Turla APT group security researchers spelled it backwards as EKANS.
Detection coverage
- 1 YARA rules
Detection rules
- TRELLIX_ARC_Snake_Ransomware (yara-rule)