freeworld
- First seen
- 2023-09-01 00:00:00
- Malware type
- ransomware
- Profile updated
- 2026-07-07 13:57:38
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications retail-and-hospitality
Context
FreeWorld is a ransomware variant first observed in September 2023, and is believed to be derived from the Mimic ransomware family. It is deployed through coordinated campaigns dubbed DB#JAMMER, which exploit poorly secured Microsoft SQL (MSSQL) servers exposed to the internet. Attackers gain initial access via brute force, leverage the xp_cmdshell feature to execute shell commands, disable defenses, deploy remote access tools like Cobalt Strike and AnyDesk, and eventually deliver the FreeWorld payload. The ransomware encrypts files using hybrid encryption and appends the .FreeWorldEncryption extension. Victims receive a ransom note titled FreeWorld-Contact.txt, directing them on payment and data recovery steps.
Reports & references
- ransomlook.io — Freeworld (report)
- Broadcom/Symantec — Freeworld Ransomware (report)
- thehackernews.com — Threat Actors Targeting Microsoft Sql (report)
- securonix.com — Securonix Threat Labs Security Advisory Threat Actors Target Mssql Servers In Dbjammer To Deliver Freeworld Ransomware (report)
- darkreading.com — Mssql Databases Under Fire From Freeworld Ransomware (report)
- pcrisk.com — 27581 Freeworld Ransomware (report)