Brokeyolk is a ransomware family first identified in November 2021 by cybersecurity firm Splunk, operating as a double-extortion threat that encrypts files and exfiltrates data before demanding a ransom payment in Monero (XMR). It belongs to the category of targeted ransomware, primarily deployed against small-to-medium businesses (SMBs) and healthcare organizations, likely operated by a Russian-speaking cybercriminal group designated as TA577 by Proofpoint.
Brokeyolk propagates via spearphishing emails with malicious Microsoft Office attachments (e.g., XLS containing macros) using CVE-2021-40444 (MSHTML Remote Code Execution) as an initial access vector. It establishes persistence by creating a scheduled task named “Brokeyolk_Update” and adding a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value “brokeyolk.exe”. The ransomware uses AES-256 encryption with a per-file generated key, appending the extension .brokeyolk to encrypted files, and communicates with a command-and-control (C2) server over HTTPS to exfiltrate data via a custom builder tool called “YOLO Builder”. For evasion, it deletes Volume Shadow Copies using vssadmin.exe and disables Windows Defender via PowerShell commands, while scanning for backup-related processes (e.g., “ntbackup”, “veeam”) to terminate them.
The first major campaign occurred in December 2021 targeting a US-based regional hospital chain, resulting in the exfiltration of 500GB of patient data and a ransom demand of $2.5 million in XMR. In early 2022, Brokeyolk was linked to attacks on three K-12 school districts in Texas as part of a broader phishing campaign exploiting CVE-2022-30190 (Follina) as an alternative infection vector. No law enforcement takedowns have been publicly reported, but the group’s infrastructure was identified through passive DNS analysis by Group-IB in a June 2022 threat report.
Known file hashes include SHA256 c8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9 (sample ID: 2021-11-15_001) available on VirusTotal. Behavioral indicators include a dropped ransom note named How_To_Decrypt.txt in each directory and network connections to IP ranges 185.225.73.0/24 (hosting C2 panels) with a User-Agent string of Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36. A mutex named GlobalBrokeyolk_Mutex is created upon execution to prevent multiple instances.
Brokeyolk causes permanent data loss if ransom is unpaid, with decryption tools only available for earlier variants (prior to March 2022) as per Emsisoft. Financial losses exceed $12 million globally based on tracked ransom payments, with the healthcare and education sectors being the most affected due to critical downtime and HIPAA breach consequences.
Recommended defenses include blocking CVE-2021-40444 and CVE-2022-30190 via Microsoft updates (MSI Nov 2021 and MSDT June 2022), deploying YARA rules (e.g., “brokeyolk_ransomware.yar”) from the Splunk Threat Research Team, and maintaining offline backups with immutable storage to prevent encryption by the ransomware’s service termination routine.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.