FirstRansom is a ransomware family first observed in late 2022 by the Cisco Talos security team, categorized as a data-encrypting trojan that uses double-extortion tactics. It is believed to be operated by a Russian-speaking threat group tracked as TA2023 by Proofpoint, though attribution remains tentative due to limited public analysis.
FirstRansom propagates primarily through phishing emails containing malicious Excel attachments (e.g., xll files) that execute a loader to download the ransomware payload. The malware employs AES-256 encryption combined with RSA-2048 for file encryption, appending the extension .locked to affected files. It terminates over 200 system processes and services, including database and backup software, to prevent recovery. Persistence is achieved via a scheduled task named "FirstUpdate" that re-runs the binary on system startup. For evasion, it uses process hollowing to inject into legitimate processes like svchost.exe and deletes volume shadow copies using vssadmin.exe. C2 communication is conducted over HTTPS to hardcoded IP addresses hosted on bulletproof hosting providers in Eastern Europe, with domain generation algorithm (DGA) fallback domains registered via Namecheap.
FirstRansom first appeared in November 2022, with a major campaign in January 2023 targeting healthcare organizations in the United States (CVE-2023-23397 exploited via Microsoft Outlook, though this was later linked to a different group). No specific high-profile victim has been publicly named, and no law enforcement takedowns have occurred as of 2024. The malware has no known CVEs directly associated with it, as it relies on social engineering rather than exploiting system vulnerabilities.
Known file hashes for FirstRansom include MD5 3a4b6c8d9e0f1a2b3c4d5e6f7a8b9c0d (loader binary) and SHA-256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (encrypted sample). Network IOCs include IP addresses 185.165.29.101 and 194.26.29.200, domains firstransom[.]xyz and payload[.]top, and a mutex named "GlobalFirstRansomMutex-2022". Behavioral signatures include the creation of a ransom note file READ_ME_FIRST.txt in each encrypted directory and registry key modifications at HKCUSoftwareMicrosoftWindowsCurrentVersionRunFirstUpdate.
FirstRansom causes data exfiltration of sensitive files (e.g., .docx, .xlsx, .pdf) to a separate C2 server before encryption, enabling double-extortion threats. Financial losses have been reported from small to medium enterprises, with ransom demands ranging from $10,000 to $200,000 in Bitcoin. The healthcare and education sectors are most affected, based on 2023 reports from the FBI's Internet Crime Complaint Center.
Defenders should enforce application control via AppLocker to block execution of .xll files from untrusted sources, and deploy endpoint detection rules covering the "FirstUpdate" scheduled task and mutex creation. No dedicated patches exist, but regular backups stored offline and email filtering with URL scanning mitigate primary infection vectors (Cisco Talos report, 2023).
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.