Skip to main content

Boteraser | Website and Server Security Solutions

Eternity Ransomware

Ransomware

⚠️ Overview

Eternity Ransomware is a ransomware-as-a-service (RaaS) family first observed in August 2022 by researchers at Cyble and subsequently tracked by Check Point and Trend Micro. It is the encryption component of the broader Eternity Threat Group’s malware suite, which also includes a stealer, clipper, and DDoS bot — collectively marketed on underground forums as “Eternity Project.” The group is believed to operate from Russian-speaking forums and offers affiliates a web-based panel for managing campaigns.

🔧 Technical Capabilities

Eternity Ransomware uses the ChaCha20 stream cipher combined with RSA-4096 to encrypt local and network-shared files, appending the extension .Eternity to each encrypted file. It deletes Volume Shadow Copies via vssadmin.exe and terminates processes and services that may interfere with encryption (e.g., database, backup software). Persistence is achieved by adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware communicates with its command-and-control (C2) server over HTTP for key exchange and victim tracking, using a unique victim ID generated by the loader. Evasion techniques include checking for sandbox environments (e.g., by testing RAM size) and avoiding Russian, Ukrainian, and Belarusian keyboard layouts as an anti-analysis measure. The initial access vector is often via phishing emails with malicious attachments (VBscripts or Office macros) that drop the loader, as observed by Intezer in September 2022.

📜 History & Notable Incidents

Eternity Ransomware first appeared on a Russian-language hacking forum in August 2022, advertised as a “stable” RaaS product with a 20% affiliate commission. In October 2022, security vendor Cyble published a detailed analysis of version 2.0, which added a “double extortion” feature — exfiltrating victim data to a public Megasync account before encryption. No high-profile corporate victims have been publicly named, but the malware has been linked to small-to-medium business attacks globally, particularly in the US and India. No specific CVEs are directly exploited; instead, it relies on phishing and stolen credentials. There have been no law enforcement takedowns reported as of early 2025.

🔍 Detection Indicators

Behavioral indicators include the creation of the ransom note !!! READ_ME_TO_DECRYPT !!!.txt in every affected directory, and the appearance of .Eternity file extension. Network indicators include HTTP POST requests to C2 domains (e.g., eternity[.]cc or eternityproject[.]top — reported by Trend Micro) with a victim ID in the URL path. File hashes are dynamic per campaign, but early samples (SHA256: 0a3b... from August 2022) are documented in VirusTotal. Mutex names include EternityMutex as observed in Cyble’s report. User-Agent strings often mimic legitimate browsers (e.g., Mozilla/5.0) to evade network filtering.

☠️ Risk & Impact

Eternity Ransomware causes irreversible file encryption, leading to operational downtime and potential data loss if backups are unavailable. The associated stealer component (Eternity Stealer) can exfiltrate browser passwords, crypto-wallet files, and FTP credentials before encryption, enabling additional financial theft. The primary sectors affected are small businesses, logistics, and education, as indicated in open-source reports by Check Point in Q4 2022.

🛡️ Mitigation

Defenders should enforce email filtering to block macro-enabled attachments, restrict vssadmin.exe execution via AppLocker or WDAC, and maintain offline backups. Network detection rules (e.g., Snort/Suricata signatures for HTTP POST to known C2 patterns) are recommended; Cyble and Trend Micro provide free YARA rules for Eternity samples. Regular patching of software vulnerabilities and user awareness training remain critical first-line defenses.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.