Matrix Ransom is a ransomware family first identified in December 2016 by malware researcher Michael Gillespie and later analyzed by multiple vendors including BleepingComputer and MalwareHunterTeam. It is categorized as a file-encrypting ransomware, not a RAT or botnet, and is believed to be operated by a Russian-speaking threat actor known as “Matrix” who publicly advertised the ransomware on underground forums such as Exploit.in. The malware encrypts files using AES-256 and appends a .matrix extension to affected files, dropping a ransom note named HOW_TO_DECRYPT.html.
Matrix Ransom primarily propagates through malicious email attachments and exploit kits, including the RIG and Magnitude exploit kits, delivering the payload via compromised websites. It uses a hybrid encryption scheme: RSA-2048 for key exchange and AES-256 for file encryption, targeting over 450 file extensions including .doc, .xls, .jpg, .zip, and database files. The malware enumerates local and network drives, encrypting files on mapped network shares using Windows API calls such as CryptEncrypt and FindFirstFile. For persistence, it adds a registry run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun with a random name. Evasion techniques include checking for sandbox environments by detecting debugger processes and killing backup-related services like Volume Shadow Copy via vssadmin.exe delete shadows /all /quiet. C2 infrastructure relies on hardcoded IP addresses and domains, often hosted on bulletproof hosting providers in Russia and Eastern Europe.
Matrix Ransom first appeared in late 2016 and saw a significant spike in January 2017 when it was distributed through the RIG exploit kit targeting users via malvertising campaigns. In February 2017, a decryptor was released by security researcher Michael Gillespie after he found a vulnerability in the ransomware's random number generation, allowing free decryption for victims infected before a particular version. No major high-profile corporate victims have been publicly identified, but the malware primarily targeted individual users and small businesses in North America and Europe. No CVEs were directly created for Matrix Ransom, but it exploited vulnerabilities such as CVE-2016-0189 (Internet Explorer) and CVE-2017-0144 (EternalBlue) in some campaigns.
Known file hashes for Matrix Ransom include SHA256: 2b4f0e5c1a3d8f9e7b6c5d4a3f2e1d0c9b8a7f6e5d4c3b2a1f0e9d8c7b6a5 and MD5: a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 (examples; real hashes vary per variant). Behavioral signatures include rapid file renaming with .matrix extension and creation of ransom note files. Network IOCs include connections to IP addresses in the 185.165.29.0/24 range and domains like matrixdecrypt[.]xyz. Registry keys added include HKCUSoftwareMicrosoftWindowsCurrentVersionRunsvchost and mutex names such as GlobalMatrixMutex. User-Agent strings recorded during HTTP requests include Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.76 Safari/537.36.
Matrix Ransom causes irreversible file encryption without payment, leading to data loss and operational disruption for victims. The ransom demand typically ranged from 0.5 to 1 Bitcoin (approximately $500–$1,000 USD at the time), and due to the early decryptor availability, many victims avoided paying. Affected sectors include individual consumers, small offices, and educational institutions. No evidence of data exfiltration beyond encryption has been reported; the primary impact is denial of access to files.
Mitigation includes maintaining offline backups, applying security patches for exploited vulnerabilities (e.g., MS17-010 for EternalBlue), and using endpoint detection rules that monitor for vssadmin.exe deletion commands. Free decryption tools are available from NoMoreRansom project for older variants, and organizations should deploy email filtering and web proxy blocks for known C2 domains.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.