Skip to content

Pandora

Pandora is ransomware reported in 2022, including activity targeting the automotive sector and deployment by the Microsoft-tracked actor DEV-0401.

Profile source: Ransomware.live opens in a new tab

Pandora

Family profile

Pandora is ransomware reported in 2022, including activity targeting the automotive sector and deployment by the Microsoft-tracked actor DEV-0401. This profile excludes the unrelated Windows backdoor and rootkit that also uses the Pandora name.

Operational record

1
YARA rules
2
Leak sites
0 available

Reporting

Research mentioning Pandora

Aug 3
Securelist

Incident response statistics and cases at educational institutions in Brazil | Securelist

Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.

Mar 9
Mitre Attack Website

Compromise Accounts, Technique T1586 - Enterprise | MITRE ATT&CKĀ®

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.