Icefire

First seen
2022-03-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-10 14:55:40
Profile updated
2026-07-07 13:49:43

Targeted industries: energy-and-utilities technology-and-telecommunications

Context

Icefire is a ransomware family known for targeting specific industries, primarily focusing on technology and critical infrastructure sectors such as energy and utilities. It is employed by threat actors to encrypt files and demand ransom for decryption, emphasizing a targeted approach rather than indiscriminate attacks.

Detection coverage

  • 1 YARA rules

Detection rules

  • SEKOIA_Ransomware_Linux_Icefire_2023 (yara-rule)

Reports & references

  • ransomlook.io — Icefire (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Icefire (report)
  • sentinelone.com — Icefire Ransomware Returns Now Targeting Linux Enterprise Networks (report)

External references