Eternity Ransomware is a ransomware-as-a-service (RaaS) family first observed in August 2022 by researchers at Cyble and subsequently tracked by Check Point and Trend Micro. It is the encryption component of the broader Eternity Threat Group’s malware suite, which also includes a stealer, clipper, and DDoS bot — collectively marketed on underground forums as “Eternity Project.” The group is believed to operate from Russian-speaking forums and offers affiliates a web-based panel for managing campaigns.
Eternity Ransomware uses the ChaCha20 stream cipher combined with RSA-4096 to encrypt local and network-shared files, appending the extension .Eternity to each encrypted file. It deletes Volume Shadow Copies via vssadmin.exe and terminates processes and services that may interfere with encryption (e.g., database, backup software). Persistence is achieved by adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware communicates with its command-and-control (C2) server over HTTP for key exchange and victim tracking, using a unique victim ID generated by the loader. Evasion techniques include checking for sandbox environments (e.g., by testing RAM size) and avoiding Russian, Ukrainian, and Belarusian keyboard layouts as an anti-analysis measure. The initial access vector is often via phishing emails with malicious attachments (VBscripts or Office macros) that drop the loader, as observed by Intezer in September 2022.
Eternity Ransomware first appeared on a Russian-language hacking forum in August 2022, advertised as a “stable” RaaS product with a 20% affiliate commission. In October 2022, security vendor Cyble published a detailed analysis of version 2.0, which added a “double extortion” feature — exfiltrating victim data to a public Megasync account before encryption. No high-profile corporate victims have been publicly named, but the malware has been linked to small-to-medium business attacks globally, particularly in the US and India. No specific CVEs are directly exploited; instead, it relies on phishing and stolen credentials. There have been no law enforcement takedowns reported as of early 2025.
Behavioral indicators include the creation of the ransom note !!! READ_ME_TO_DECRYPT !!!.txt in every affected directory, and the appearance of .Eternity file extension. Network indicators include HTTP POST requests to C2 domains (e.g., eternity[.]cc or eternityproject[.]top — reported by Trend Micro) with a victim ID in the URL path. File hashes are dynamic per campaign, but early samples (SHA256: 0a3b... from August 2022) are documented in VirusTotal. Mutex names include EternityMutex as observed in Cyble’s report. User-Agent strings often mimic legitimate browsers (e.g., Mozilla/5.0) to evade network filtering.
Eternity Ransomware causes irreversible file encryption, leading to operational downtime and potential data loss if backups are unavailable. The associated stealer component (Eternity Stealer) can exfiltrate browser passwords, crypto-wallet files, and FTP credentials before encryption, enabling additional financial theft. The primary sectors affected are small businesses, logistics, and education, as indicated in open-source reports by Check Point in Q4 2022.
Defenders should enforce email filtering to block macro-enabled attachments, restrict vssadmin.exe execution via AppLocker or WDAC, and maintain offline backups. Network detection rules (e.g., Snort/Suricata signatures for HTTP POST to known C2 patterns) are recommended; Cyble and Trend Micro provide free YARA rules for Eternity samples. Regular patching of software vulnerabilities and user awareness training remain critical first-line defenses.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.