Netskope Threat Labs

EKANS

ATP Sandbox Adv. HeuristicsAV

EKANS is a Golang ransomware that first appeared in mid December 2019 and hit sectors including energy, healthcare, and automotive manufacturing, sometimes causing significant operational disruptions. It checked running processes against a hard-coded kill list that included ICS software platforms such as GE Proficy and Honeywell HMIWeb, showing deliberate targeting of industrial environments.

First seen
March 2022
Last seen
October 2026

9 techniques across 5 tactics.

TA0002 Execution

  • T1047Windows Management Instrumentation

TA0005 Stealth

  • T1027Obfuscated Files or Information
  • T1036Masquerading
    • T1036.005Match Legitimate Resource Name or Location

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1057Process Discovery

TA0040 Impact

  • T1486Data Encrypted for Impact
  • T1489Service Stop
  • T1490Inhibit System Recovery

TA0112 Defense Impairment

  • T1685Disable or Modify Tools
Alert Name
Gen:Variant.Ransom.Ekans.1
Gen:Variant.Ransom.Ekans.3
Win32.Ransomware.Ekans