WHIRLPOOL

First seen
2022-01-15 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:09:40

Targeted industries: financial-services government-and-public-sector

Targeted regions: country_code:us

Context

WHIRLPOOL is a ransomware family primarily targeting financial services and government sectors. It was first observed in early 2022, known for its disruptive encryption tactics aimed at US-based organizations.

Detection coverage

  • 1 YARA rules

Detection rules

  • SIGNATURE_BASE_APT_MAL_LNX_Hunting_Linux_WHIRLPOOL_1 (yara-rule)

Reports & references

  • cloud.google.com — Barracuda Esg Exploited Globally (report)
  • youtube.com — Watch (report)
  • sansorg.egnyte.com — 8Ekljcphpj (report)
  • CISA — Mar 10459736.R1.V1.Clear (report)
  • CISA — Mar 10454006.R4.V2.Clear (report)
  • CISA — Mar 10454006.R5.V1.Clear 0 (report)
  • services.google.com — 01 Chinese Espionage Article M Trends 2024 (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Whirlpool (report)
  • CISA — Ar23 250A 0 (report)

External references