Skip to content

Satana

Satana is a Windows ransomware family first observed in 2016 that combines file encryption with destructive boot-disk tampering.

Profile source: Mallory opens in a new tab

Satana

Family profile

Satana is a Windows ransomware family first observed in 2016 that combines file encryption with destructive boot-disk tampering. It is notable for overwriting the Master Boot Record and encrypting files on the victim system, blending behaviors associated with both ransomware and bootlocker-style malware. Analyses of related ransomware families have highlighted Satana’s use of direct physical-drive access for MBR modification and a normal reboot mechanism to activate its boot-stage effects.

Satana has been discussed in comparative research on MBR-targeting ransomware because its implementation differs from Petya-derived families in several key areas, including how it accesses the system drive and how it triggers reboot. It has also been cited as an example of ransomware using file-mapping APIs for in-place file encryption, an uncommon implementation detail later echoed by other malware.

Genealogical analysis has linked Satana to the later CoronaVirus ransomware family. In that lineage, CoronaVirus retained the combination of MBR modification and file encryption while adding boot-time lock-screen behavior and serving as cover for deployment of the Kpot information stealer. This relationship indicates Satana’s influence on subsequent ransomware that combined extortion with broader post-compromise monetization.

Satana targets Windows systems and is primarily characterized as ransomware due to its encryption and boot disruption behavior. High-confidence reporting supports destructive modification of boot structures, encryption of victim files, and reboot-driven activation of its ransom functionality.

Capabilities

  • Exfiltration

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 7, 2026
Last activity
Sep 7, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • RU1

Leading providers

  • Kontel LLC1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

Satana in ATT&CK

3 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.