Skip to main content
Mallory
MalwareRansomwareUsed by 2 actorsExploits 1 CVE

FIVEHANDS

FiveHands is a ransomware family described as a rewrite of DEATHRANSOM, observed by Mandiant in January and February 2021 at multiple extorted victims. It has been linked to financially motivated intrusions involving the UNC2447 cluster and was also reported by Microsoft as developed and deployed by DEV-0230, a prolific Conti affiliate that also deployed HelloKitty. Mandiant reported exploitation of the SonicWall SMA 100 zero-day CVE-2021-20016 beginning in January 2021 to deploy FiveHands, and noted targeting in Europe and North America in UNC2447-related activity.

Documented capabilities include encrypting data for ransom using an embedded NTRU public key, enumerating network shares and mounted drives, accepting a command-line argument to restrict encryption to specified directories, using WMI to delete files on target machines, and deleting volume shadow copies on compromised hosts to inhibit recovery. Mandiant also reported a newer FiveHands variant and noted observations suggesting a link to UNC2447. The malware has been observed alongside the SOMBRAT backdoor in ransomware intrusions. Reported associated tooling and intrusion activity in related campaigns included WARPRISM, Cobalt Strike BEACON, FOXGRABBER, ADFIND, BLOODHOUND, MIMIKATZ, RCLONE, ROUTERSCAN, S3BROWSER, ZAP, and 7ZIP. High-confidence context indicates FiveHands was used in extortion operations and in some cases accompanied by threats of media exposure and sale of stolen data.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2021-20016SQL Injection in SonicWall SMA100 SSL VPNExploited in the wild

Mandiant said in April that the CVE-2021-20016 SMA 100 zero-day was exploited to deploy a new ransomware strain known as FiveHands starting with January...

via bleeping computerbleepingcomputer.com
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
DEV-0230

One of the most prolific and successful Conti affiliates—and the one responsible for developing the “Conti Manual” leaked in August 2021—is tracked as DEV-0230. This activity group also developed and deployed the FiveHands and HelloKitty ransomware payloads...

via microsoft generalmicrosoft.com
UNC2447

In January and February 2021, Mandiant Consulting observed a novel rewrite of DEATHRANSOM—dubbed FIVEHANDS—along with SOMBRAT at multiple victims that were extorted.

via fireeyefireeye.com
MITRE ATT&CK

Techniques & procedures

12 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

3 techniques
T1047Windows Management InstrumentationEvidence3
TacticExecution

The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'

T1059Command and Scripting InterpreterEvidence2
TacticExecution

APT19 downloaded and launched code within a SCT file; APT32 used COM scriptlets to download Cobalt Strike beacons; APT37 used Ruby scripts to execute payloads; ArcaneDoor included the adversary executing command line interface (CLI) commands.

T1059.003Windows Command ShellEvidence2
TacticExecution

Dragonfly has used the command line for execution. Empire uses a command-line interface to interact with systems. StarProxy has used the command line for execution of commands.

Stealth

4 techniques
T1027Obfuscated Files or InformationEvidence5
TacticStealth

The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.

T1027.013Encrypted/Encoded FileEvidence2
TacticStealth

Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'

T1070.004File DeletionEvidence1
TacticStealth

Examples include 'FIVEHANDS can use WMI to delete files on a target machine' and 'FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities.'

T1140Deobfuscate/Decode Files or InformationEvidence4
TacticStealth

The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'

Discovery

2 techniques
T1083File and Directory DiscoveryEvidence3
TacticDiscovery

"...has a command to retrieve metadata for files on disk as well as a command to list the current working directory." / "...can list files and directories." / "...used the following commands... to obtain information about files and directories: dir c:\ >> %temp%\download ..."

T1135Network Share DiscoveryEvidence1
TacticDiscovery

Lateral Movement

1 technique
T1210Exploitation of Remote ServicesEvidence1

"...multiple security flaws... impact SMA 200, 210, 400, 410, and 500v appliances even when the web application firewall (WAF) is enabled."

Impact

2 techniques
T1486Data Encrypted for ImpactEvidence5
TacticImpact

Attackers move directly to deploying ransomware by editing a Group Policy.

T1490Inhibit System RecoveryEvidence3
TacticImpact

Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.

INDICATORS OF COMPROMISE

IOCs tracked for this family

11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
11 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.md5●●●●●●●●●●●●View more in app5 years ago
hash.md5●●●●●●●●●●●●View more in app5 years ago
hash.md5●●●●●●●●●●●●View more in app5 years ago
hash.md5●●●●●●●●●●●●View more in app5 years ago
hash.md5●●●●●●●●●●●●View more in app5 years ago
hash.md5●●●●●●●●●●●●View more in app5 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching11

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping12

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.