Hunt
Aliases: Hunt-Dharma-Crysis
- First seen
- 2016-07-01 00:00:00
- Malware type
- ransomware
- Profile updated
- 2026-07-07 16:19:35
Targeted industries: healthcare-and-pharmaceutical financial-services government-and-public-sector education-and-nonprofits retail-and-hospitality
Context
Hunt ransomware is a variant of the Dharma/CrySIS ransomware family. This variant creates a unique ID for each victim, appends the extension '.hunt' to encrypted files, and leaves a ransom note known as info-hunt.txt. The Dharma/CrySIS ransomware family emerged around mid-2016 as a Ransomware-as-a-Service (RaaS) program, utilizing various initial intrusion methods such as phishing, disguising as legitimate software, and exploiting open RDP connections. This variant uses AES-256 encryption (CBC mode) or DES+RSA and demands payment to recover files. Upon execution, the ransomware generates a 256-bit AES decryption key, which is then encrypted along with random bytes using the RSA-1024 algorithm and stored at the end of the encrypted file. The ransomware is written in C/C++ and compiled using MS Visual Studio. Regarding geographic attribution, it has been identified in use by threat actors from Russia, Ukraine, India, and other countries.
Detection coverage
- 11 YARA rules
Detection rules
- SBOUSSEADEN_Susp_Msoffice_Addins_Wxll (yara-rule)
- SBOUSSEADEN_Mimikatz_Memssp_Hookfn (yara-rule)
- SBOUSSEADEN_Hunt_Susp_Vhd (yara-rule)
- SBOUSSEADEN_Mimikatz_Kiwikey (yara-rule)
- DITEKSHEN_MALWARE_Win_Fyanti (yara-rule)
- DITEKSHEN_MALWARE_Win_Dllhijacker01 (yara-rule)
- DITEKSHEN_MALWARE_Win_Hello (yara-rule)
- DITEKSHEN_MALWARE_Win_Turian (yara-rule)
- DITEKSHEN_MALWARE_Win_Avoslocker (yara-rule)
- DITEKSHEN_MALWARE_Win_Romcom_Loader (yara-rule)
- DITEKSHEN_MALWARE_Win_Romcom_Dropper (yara-rule)
Related threat objects
- Dharma Ransomware (malware)
- Virus-Encoder (malware)