Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomware

Mamba

Mamba, also referred to as HDDCrypt or HDDCryptor, is a ransomware family first reported in 2016 that encrypts entire hard drive partitions rather than only individual files. It uses disk-level cryptography and leverages the open-source DiskCryptor utility to encrypt disks, then writes a custom boot loader to the master boot record (MBR), preventing the infected system from booting normally and displaying its own ransom screen at startup. Reported ransom demands included one Bitcoin.

High-confidence reporting in the provided content states that Mamba was initially discovered by Morphus Labs in Brazil, with infections also identified in the United States and India. It was believed to spread through phishing emails and malicious downloads. The malware was described as using legitimate tools including DiskCryptor and Netpass, and using dccon.exe and mount.exe during encryption activity, including encrypting local files and mapped network drives.

The ransom note text cited in the content included: "You are Hacked ! H.D.D. Encrypted , Contact Us For Decryption Key", with contact email w889901665@yandex.com and a victim identifier field such as "YOURID: 123152". The malware has been compared to Petya because both manipulate the boot process, but the provided reporting emphasizes that Mamba relies on whole-partition disk encryption rather than traditional file-by-file encryption. Additional reporting in the content notes that new variants were observed in the second half of 2019 and that Mamba gained traction again in attacks around Q1 2020.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1189Drive-by CompromiseEvidence1

According to Renato Marinho, a researcher at Morphus Labs, the malware is believed to be spread through phishing emails and malicious downloads.

T1566PhishingEvidence1

According to Renato Marinho, a researcher at Morphus Labs, the malware is believed to be spread through phishing emails and malicious downloads.

Persistence

1 technique
T1542.001System FirmwareEvidence1

Once it infects a machine, it overwrites the host computer's Master Boot Record (MBR) with its own variant, and from there, it will now be able to encrypt the hard drive.

Stealth

1 technique
T1542.001System FirmwareEvidence1

Once it infects a machine, it overwrites the host computer's Master Boot Record (MBR) with its own variant, and from there, it will now be able to encrypt the hard drive.

Credential Access

1 technique
T1555Credentials from Password StoresEvidence1

It utilizes Netpass, a free network password recovery tool, as well as DiskCryptor, an open source disk encryption utility.

Discovery

1 technique
T1135Network Share DiscoveryEvidence1

It will then use two programs called "dccon.exe." and "mount.exe," which are responsible for encrypting the files on the computer, and all mapped network drives.

Impact

3 techniques
T1486Data Encrypted for ImpactEvidence1

A variant of ransomware has been discovered, which encrypts not only files, but the entire hard drive as well... It will then use two programs called "dccon.exe." and "mount.exe," which are responsible for encrypting the files on the computer, and all mapped network drives.

T1529System Shutdown/RebootEvidence1

This would mean that if the computer is opened, the system would not fully load, and it would only display a screen controlled by the Mamba ransomware. It will refuse to boot the PC unless the decryption key is provided.

T1561Disk WipeEvidence1

In a recent LockBit attack, the MBR was overwritten with roughly 2000 bytes; The infected machine would not boot up unless a password is supplied.

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Other
1 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
email●●●●●●●●●●●●View more in app1 month ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.