Thor

First seen
2016-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-10 23:57:26
Profile updated
2026-07-07 13:47:55

Targeted industries: healthcare-and-pharmaceutical financial-services government-and-public-sector

Context

Thor ransomware encrypts files on the infected system and demands a ransom for decryption keys. It is part of the larger suite of ransomware families known for targeting various industries and has significant impacts on financial services and critical infrastructures.

Detection coverage

  • 2 YARA rules

Detection rules

  • ARKBIRD_SOLG_Mal_Plugx_Thor_July_2021_1 (yara-rule)
  • SIGNATURE_BASE_SUSP_THOR_Unsigned_Oct23_1 (yara-rule)

Reports & references

  • ransomlook.io — Thor (report)

External references