Skip to content

Hakbit

Hakbit is a Windows .NET ransomware family associated with the broader Thanos ransomware lineage and ransomware-as-a-service ecosystem.

Profile source: Mallory opens in a new tab

Hakbit

Family profile

Hakbit is a Windows .NET ransomware family associated with the broader Thanos ransomware lineage and ransomware-as-a-service ecosystem. First observed in late 2019, it encrypts files on individual systems and corporate networks and demands payment for recovery. Early Hakbit samples were notable for weaker or flawed encryption implementations that enabled decryption in some cases, while later related Thanos-derived variants adopted stronger RSA-based schemes that generally prevented recovery without the private key.

Hakbit and closely related Thanos builds support extensive operator customization through a builder, including configurable ransom notes and file extensions, delayed execution, self-deletion, code obfuscation, anti-analysis measures, Windows Defender interference, AMSI bypass, and victim notification features. Observed behavior includes deletion or forced removal of Volume Shadow Copy data to inhibit recovery, process termination aimed at analysis and forensic tools, delayed execution, and in some variants attempts to modify system settings related to privilege handling and recovery. Some Thanos-linked deployments also monitored newly attached storage volumes for encryption and used in-memory execution chains involving PowerShell, inline C#, and shellcode loaders.

Distribution associated with Hakbit and its Thanos-derived variants has included exposed remote administration services, spam and malicious attachments, deceptive downloads, malvertising, fake updates, exploit-driven delivery, botnet-assisted spread, and trojanized software installers. In enterprise intrusions, related variants have also been observed spreading laterally with stolen credentials over SMB and remote execution mechanisms. The family has targeted Windows environments, including state-run organizations and enterprise networks, and has evolved through multiple renamed or customized variants such as Abarcy, Corona, and Ravack before broader identification under the Thanos name. Some Hakbit-classified infections remain decryptable with public tools, but corrected later Thanos variants typically are not.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Scanning

Observed infrastructure

Last seven days

First activity
Sep 17, 2026
Last activity
Sep 17, 2026
Feed role
Distribution
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • Nocix, LLC1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

Hakbit in ATT&CK

11 distinct techniques

Reporting

Research mentioning Hakbit

Dec 5
Id Ransomware

Шифровальщики-вымогатели The Digest "Crypto-Ransomware": RedRum, Tycoon

Tycoon, also tracked as RedRum, Grinch, and in some reporting alongside Thanos-linked variants, emerged as a manually deployed ransomware threat against enterprise environments on both Windows and Linux. Operators were reported to gain access through vulnerable or exposed RDP services, then encrypt files with AES-256-GCM while protecting encryption keys with RSA-1024. The malware appended extensions including .redrum, .grinch, .thanos, .eruption, and .magneto, and dropped a ransom note named decryption.txt using contact addresses such as moncler@tutamail.com and moncler@cock.li. Reporting also tied the activity to broader Thanos ransomware development, a .NET-based RaaS ecosystem that enabled extensive customization, persistence, anti-analysis, and defense-evasion features across multiple later variants. The malware was described as deleting shadow copies and disabling recovery and firewall protections while avoiding some system files and directories to keep infected systems operational. Historical tracking indicates some early Hakbit-identified and RedRum samples could be decrypted, including with an Emsisoft decryptor, while later corrected Thanos-derived variants adopted stronger RSA-based encryption that generally prevented recovery without the attackers' private key.

Oct 1
Id Ransomware

Шифровальщики-вымогатели The Digest "Crypto-Ransomware": Hakbit, Thanos

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.