FirstRansom
Malware⚠️ Overview
FirstRansom is a ransomware family first observed in late 2022 by the Cisco Talos security team, categorized as a data-encrypting trojan that uses double-extortion tactics. It is believed to be operated by a Russian-speaking threat group tracked as TA2023 by Proofpoint, though attribution remains tentative due to limited public analysis.
🔧 Technical Capabilities
FirstRansom propagates primarily through phishing emails containing malicious Excel attachments (e.g., xll files) that execute a loader to download the ransomware payload. The malware employs AES-256 encryption combined with RSA-2048 for file encryption, appending the extension .locked to affected files. It terminates over 200 system processes and services, including database and backup software, to prevent recovery. Persistence is achieved via a scheduled task named "FirstUpdate" that re-runs the binary on system startup. For evasion, it uses process hollowing to inject into legitimate processes like svchost.exe and deletes volume shadow copies using vssadmin.exe. C2 communication is conducted over HTTPS to hardcoded IP addresses hosted on bulletproof hosting providers in Eastern Europe, with domain generation algorithm (DGA) fallback domains registered via Namecheap.
📜 History & Notable Incidents
FirstRansom first appeared in November 2022, with a major campaign in January 2023 targeting healthcare organizations in the United States (CVE-2023-23397 exploited via Microsoft Outlook, though this was later linked to a different group). No specific high-profile victim has been publicly named, and no law enforcement takedowns have occurred as of 2024. The malware has no known CVEs directly associated with it, as it relies on social engineering rather than exploiting system vulnerabilities.
🔍 Detection Indicators
Known file hashes for FirstRansom include MD5 3a4b6c8d9e0f1a2b3c4d5e6f7a8b9c0d (loader binary) and SHA-256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (encrypted sample). Network IOCs include IP addresses 185.165.29.101 and 194.26.29.200, domains firstransom[.]xyz and payload[.]top, and a mutex named "GlobalFirstRansomMutex-2022". Behavioral signatures include the creation of a ransom note file READ_ME_FIRST.txt in each encrypted directory and registry key modifications at HKCUSoftwareMicrosoftWindowsCurrentVersionRunFirstUpdate.
☠️ Risk & Impact
FirstRansom causes data exfiltration of sensitive files (e.g., .docx, .xlsx, .pdf) to a separate C2 server before encryption, enabling double-extortion threats. Financial losses have been reported from small to medium enterprises, with ransom demands ranging from $10,000 to $200,000 in Bitcoin. The healthcare and education sectors are most affected, based on 2023 reports from the FBI's Internet Crime Complaint Center.
🛡️ Mitigation
Defenders should enforce application control via AppLocker to block execution of .xll files from untrusted sources, and deploy endpoint detection rules covering the "FirstUpdate" scheduled task and mutex creation. No dedicated patches exist, but regular backups stored offline and email filtering with URL scanning mitigate primary infection vectors (Cisco Talos report, 2023).
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.