Void
Aliases: VoidCrypt
- First seen
- 2021-06-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-18 21:56:57
- Profile updated
- 2026-07-07 13:49:13
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications manufacturing professional-services
Context
Void, also known as VoidCrypt, is a ransomware family known for encrypting files and demanding a ransom in cryptocurrency. It has targeted various industries without significant geopolitical preference.
Detection coverage
- 4 YARA rules
Used by threat actors
- Void Banshee Zero-Day Exploit Activity (campaign)
Detection rules
- DITEKSHEN_MALWARE_Win_Spyro (yara-rule)
- SEKOIA_Ransomware_Win_Voidcrypt (yara-rule)
- ARKBIRD_SOLG_MAL_Zstealer_Nov_2021_1 (yara-rule)
- MALPEDIA_Win_Void_Auto (yara-rule)
Reports & references
- Kaspersky — 104452 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Void (report)
- github.com — Aodin Vo1D Malware (report)
- id-ransomware.blogspot.com — Void Voidcrypt Ransomware (report)