EKANS

Aliases: SNAKEHOSE

Family
Malware family
Operating systems
windows
Last IoC activity
2026-07-22 01:29:31
Profile updated
2026-07-07 11:27:56

Context

EKANS is ransomware that was first seen December 2019 and later reported to have impacted operations at Honda automotive production facilities. EKANS has a hard-coded kill-list of processes, including some associated with common ICS software platforms (e.g., GE Proficy historian, Honeywell HMIWeb). If the malware discovers these processes on the target system, it will stop, encrypt, and rename the process to prevent the program from restarting. This malware should not be confused with the “Snake” malware associated with the Turla group. The ICS processes documented within the malware’s kill-list is similar to those defined by the MEGACORTEX software.The ransomware was initially reported as “Snake”, however, to avoid confusion with the unrelated Turla APT group security researchers spelled it backwards as EKANS.

Detection coverage

  • 1 YARA rules

Detection rules

  • TRELLIX_ARC_Snake_Ransomware (yara-rule)

External references