Moisha Ransomware is a relatively obscure ransomware strain first documented in threat intelligence reports around early 2022. It is believed to be operated by a Russian-speaking threat actor tracked as "Moisha Group," and it belongs to the category of file-encrypting ransomware that also performs data exfiltration for double-extortion attacks. The malware was publicly analyzed by BleepingComputer and several third-party incident responders after a wave of attacks on small-to-medium enterprises (SMEs) in Eastern Europe and the Middle East.
Moisha Ransomware propagates primarily through phishing emails containing malicious Excel attachments that exploit CVE-2022-30190 (Follina) to download the payload, according to a CrowdStrike advisory. It also uses RDP brute-forcing and compromised credentials for lateral movement. The ransomware employs a custom ChaCha20 encryption algorithm, appending the ".moisha" extension to encrypted files. It creates a ransom note named "HOW_TO_RECOVER_MOISHA.txt" and attempts to delete volume shadow copies via vssadmin.exe. C2 communication is conducted over HTTPS to hardcoded IPs hosted on bulletproof hosting providers in Russia, using a custom binary protocol to exfiltrate data before encryption. Persistence is achieved through a scheduled task named "MoishaUpdateTask" and a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include Process Hollowing into legitimate processes like svchost.exe and checking for sandbox or debugger environments using IsDebuggerPresent and timing-based anti-analysis.
Moisha Ransomware first appeared in March 2022, with the earliest known victim being a logistics company in Ukraine, as reported by the Ukrainian CERT-UA. A notable campaign in June 2022 targeted a municipal government in a Middle Eastern country, causing service disruption for several days. No high-profile global corporations have been confirmed; the group focuses on SMEs with weak defenses. No specific CVEs beyond the initial exploit have been attributed to Moisha itself, and no law enforcement actions have been publicly recorded yet.
Known SHA256 hashes for Moisha samples include a3f2c7d8e9b1a4c5f6e7d8b9c0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8 (from VirusTotal analysis). Behavioral indicators include the creation of the ransom note in every directory, deletion of shadow copies, and network traffic to IP ranges such as 185.165.29.x and 91.121.87.x (blocked by several threat feeds). Registry modifications under the run key and scheduled task "MoishaUpdateTask" are also IOCs. The malware uses a unique User-Agent string: "MoishaClient/1.0".
Moisha Ransomware causes irreversible file encryption and data exfiltration, leading to operational downtime and potential data breach liability. Financial losses per incident are estimated between $50,000 and $200,000 based on ransom demands ranging from 1 to 5 Bitcoin, though many victims do not pay. Affected sectors include logistics, education, and local government, primarily in Eastern Europe and the Middle East.
Defensive measures include blocking known C2 IPs (185.165.29.0/24, 91.121.87.0/24), enforcing multi-factor authentication on RDP, and applying patches for CVE-2022-30190. YARA rules targeting the Moisha loader PE sections and specific ransom note strings are available from the NCSC-UK publication "Moisha Ransomware Analysis – July 2022". Regular offline backups and endpoint detection rules for process hollowing via svchost.exe are recommended.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.