Heimdall
- First seen
- 2022-07-15 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:36:25
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications
Context
Heimdall is a ransomware that encrypts files and appends a specific marker 'Heimdall---'. It primarily targets industries that handle significant amounts of sensitive data, such as financial services and healthcare.
Detection coverage
- 2 YARA rules
Detection rules
- SIGNATURE_BASE_MAL_WIN_Megazord_Apr25 (yara-rule)
- SIGNATURE_BASE_MAL_WIN_Akira_Apr25 (yara-rule)
Reports & references
- bleepingcomputer.com — Heimdall Open Source Php Ransomware Targets Web Servers (report)
- id-ransomware.blogspot.com — Heimdall Ransomware (report)