MuddyWater has previously attempted to deploy ransomware, such as Thanos, on victim networks to either destroy evidence of their intrusions or disrupt operations.
Thanos
Thanos is a .NET-based ransomware family and ransomware-as-a-service offering that emerged in late 2019 and was publicly identified in early 2020.
Thanos
Family profile
Thanos is a .NET-based ransomware family and ransomware-as-a-service offering that emerged in late 2019 and was publicly identified in early 2020. Written in C#, it was marketed with a builder that allowed affiliates and other operators to generate customized variants, contributing to broad downstream reuse after the builder or source code leaked. Thanos became an important progenitor for several later ransomware operations and variants, including Prometheus, Haron, Spook, Midas, and AlumniLocker, although code overlap alone does not always prove common operators.
Thanos is designed for Windows environments and supports a wide range of enterprise-impacting behaviors beyond file encryption. Reported capabilities include process injection, anti-analysis checks, anti-sniffer and anti-termination protections, persistence through Startup-folder artifacts, service and process termination to unlock files and disable defenses, deletion of shadow copies and backups, and modification of firewall or system settings to facilitate execution and recovery inhibition. Some variants also implement network spreading or lateral movement features, including use of remote execution tooling against other Windows hosts. Thanos has been observed using RIPlace, a file-rename evasion technique intended to bypass some anti-ransomware and EDR protections, and using ProcessHide to hook system APIs and conceal its process from user-space monitoring tools.
Encryption behavior varies across variants and over time. Multiple reports describe Thanos using hybrid encryption schemes combining symmetric file encryption with asymmetric protection of keys, while some descendants use Salsa20-based routines. The family commonly drops ransom notes in text and HTA formats and has been associated with double-extortion operations in which operators claim to steal data before or during encryption and threaten public release if victims do not pay.
Thanos has been distributed through several intrusion paths. Observed delivery mechanisms include phishing emails with malicious attachments or lures, malicious document and script chains, PowerShell-based loaders, and deployment after prior compromise by access brokers or loaders. It has also been linked to affiliate ecosystems and underground forum advertising. In one notable state-linked context, Iranian actor MuddyWater was assessed to have attempted deployment of a destructive Thanos variant via the PowGoop loader, apparently to disrupt operations or destroy evidence rather than for straightforward financial extortion.
The family has affected organizations across multiple sectors and geographies through both criminal and suspected state-linked activity. Its leaked builder and flexible feature set made it a durable foundation for follow-on ransomware campaigns throughout 2021 and beyond.
Capabilities
- Defense Evasion
- Exfiltration
- Extortion
- Lateral Movement
- Persistence
- Process Injection
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
3 named in public reportingCyble researchers have found a sample of the Thanos ransomware being used by the Prometheus group for a recent ransomware attack.
"...overlap between targeted intrusion operations by STATIC KITTEN and disruption-oriented Thanos ransomware activity..."
MITRE ATT&CK
Thanos in ATT&CK
23 distinct techniquesTechniques
23 techniquesReporting
Research mentioning Thanos
Iranian APT: New Methods to Target Turkey, Arabian Peninsula
Iranian state-linked threat group MuddyWater targeted governments, ministries, universities, telecommunications providers, and other organizations in Turkey, the Arabian Peninsula, Pakistan, Armenia, and nearby countries with evolving espionage malware campaigns. Researchers said the group delivered malicious Excel and Office documents through phishing, using macros and the Office exploit CVE-2017-0199 to launch multi-stage infections that dropped Windows Script Files, persistence components, and remote access tools including SloughRAT—also tracked as Canopy—along with additional Visual Basic and JavaScript implants. The intrusion chains used compromised or attacker-controlled infrastructure, regional decoy themes tied to Tajikistan, Pakistan, and Kurdistan, and fallback behavior that sometimes redirected victims to benign sites when command-and-control failed. Cisco Talos and Clearsky reported that MuddyWater combined PowerShell, living-off-the-land binaries, DNS and HTTP command-and-control, token-tracking mechanisms, and staged payload retrieval to execute arbitrary commands on victim systems, underscoring a broader shift toward more flexible and advanced tradecraft aligned with Iranian intelligence objectives.
EternityTeam: A New Prominent Threat Group
EternityTeam has emerged as a prominent malware seller on Russian-speaking underground forums and Telegram, marketing a modular malware-as-a-service toolkit that includes an infostealer, worm, miner, clipper, botnet/dropper, and ransomware. Researchers said the group has been active since at least 2022 and has paired aggressive advertising with customer support, release notes, and builder-style customization that lets buyers assemble malware binaries from separately sold components, lowering the barrier to entry for less-skilled attackers. The group's flagship offering, Eternity Stealer, is a .NET infostealer sold on subscription that targets browser data, cryptocurrency wallet information, application credentials, and Growtopia accounts. Observed samples masqueraded as Growtopia-related tools, exfiltrating stolen data over HTTPS to EternityTeam-controlled servers before forwarding it to operators through a Telegram bot. Researchers also reported samples in the wild and noted that parts of the stealer may reuse code from earlier public or criminal projects, but assessed the broader Eternity ecosystem as a credible and scalable threat because of its active distribution, modular design, and ransomware-capable tooling.
Eternity malware kit offers stealer, miner, worm, ransomware tools
Iranian Hackers Targeting Turkey and Arabian Peninsula in New Malware Campaign
Iranian linked conglomerate MuddyWater comprised of regionally focused subgroups
Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks
New in Ransomware AlumniLocker Humble Feature Different Extortion Techniques | Trend Micro (US)
Researchers identified two ransomware families, AlumniLocker and Humble, that pair file encryption with increasingly coercive pressure on victims. AlumniLocker, described as a Thanos variant, was delivered through a malicious PDF invoice lure and a downloader chain, then demanded 10 bitcoins while threatening to publish stolen data on a “wall of shame” site within 48 hours if payment was not made. Humble used a batch-file-based execution chain packaged with Bat2Exe, blocked explorer.exe access to local drives, and reported successful infections through a Discord webhook. Trend Micro said some Humble variants also threatened to rewrite the Master Boot Record (MBR) or delete files if victims refused to pay, underscoring how ransomware operators were expanding beyond encryption into data-leak threats and destructive intimidation.
Шифровальщики-вымогатели The Digest "Crypto-Ransomware": RedRum, Tycoon
Tycoon, also tracked as RedRum, Grinch, and in some reporting alongside Thanos-linked variants, emerged as a manually deployed ransomware threat against enterprise environments on both Windows and Linux. Operators were reported to gain access through vulnerable or exposed RDP services, then encrypt files with AES-256-GCM while protecting encryption keys with RSA-1024. The malware appended extensions including .redrum, .grinch, .thanos, .eruption, and .magneto, and dropped a ransom note named decryption.txt using contact addresses such as moncler@tutamail.com and moncler@cock.li. Reporting also tied the activity to broader Thanos ransomware development, a .NET-based RaaS ecosystem that enabled extensive customization, persistence, anti-analysis, and defense-evasion features across multiple later variants. The malware was described as deleting shadow copies and disabling recovery and firewall protections while avoiding some system files and directories to keep infected systems operational. Historical tracking indicates some early Hakbit-identified and RedRum samples could be decrypted, including with an Emsisoft decryptor, while later corrected Thanos-derived variants adopted stronger RSA-based encryption that generally prevented recovery without the attackers' private key.