Netskope Threat Labs

DEATHRANSOM

ATP Sandbox Adv. HeuristicsAV

DEATHRANSOM is a ransomware variant that first circulated as scareware, claiming to encrypt files that it had not touched, before its operators added genuine encryption in later builds. It spreads through spam emails and compromised remote services, and it drops ransom notes demanding payment from Windows users. The family's shift from fake to real encryption shows how quickly criminal operators iterate when early versions fail to generate revenue.

First seen
March 2022
Last seen
October 2026
DeathRansomDeathransom

9 techniques across 4 tactics.

TA0002 Execution

  • T1047Windows Management Instrumentation

TA0007 Discovery

  • T1083File and Directory Discovery
  • T1135Network Share Discovery
  • T1614System Location Discovery
  • T1680Local Storage Discovery

TA0011 Command and Control

TA0040 Impact

  • T1486Data Encrypted for Impact
  • T1490Inhibit System Recovery
Alert Name
Binary.Ransomware.DeathRansom
Gen:Variant.Ransom.Deathransom.13
Gen:Variant.Ransom.Deathransom.14
Gen:Variant.Ransom.Deathransom.16
Gen:Variant.Ransom.DeathRansom.28
Gen:Variant.Ransom.DeathRansom.3
Gen:Variant.Ransom.DeathRansom.5
Gen:Variant.Ransom.DeathRansom.7
Trojan.Ransom.DeathRansom.A
Trojan.Ransom.Deathransom.B