MrDec
Malware⚠️ Overview
MrDec is a ransomware variant first documented in November 2021 by the MalwareHunterTeam, designed to encrypt files and append the .MrDec extension. It is attributed to an unknown threat actor and operates as a file-encrypting ransomware, typically delivered through malicious email attachments or compromised RDP connections. According to BleepingComputer reports, MrDec demands a ransom of approximately 0.05 BTC (about $2,500 at the time) for decryption.
🔧 Technical Capabilities
MrDec employs AES-256 encryption combined with RSA-2048 for key protection, targeting over 200 file types including documents, databases, and multimedia files. It propagates via phishing campaigns with weaponized Office documents and exploits weak RDP credentials through brute-force attacks. The malware communicates with its C2 server over HTTP to exfiltrate system information and encryption keys, using a hardcoded IP address rather than a domain for resilience. For persistence, MrDec adds itself to the Windows Registry under HKCUSoftwareMicrosoftWindowsCurrentVersionRun as a random alphanumeric string. It evades detection by terminating processes that may lock files (e.g., SQL Server, Outlook) and deleting Volume Shadow Copies via vssadmin.exe. Additionally, MrDec disables Windows Defender through PowerShell commands and modifies the boot configuration data to prevent recovery.
📜 History & Notable Incidents
MrDec first appeared in late 2021 with a small-scale campaign targeting small and medium businesses (SMBs) in the United States and Europe. No high-profile victims have been publicly disclosed, and no CVEs are directly associated with the malware; it relies on social engineering and weak credentials. Law enforcement actions have not been reported against its operators. Academic analysis by the University of Amsterdam’s ransomware tracker (2022) catalogued MrDec as a low-sophistication variant with limited distribution.
🔍 Detection Indicators
Known SHA-256 hash of a MrDec sample is 3f4b8c2e1a0d9f8e7b6a5c4d3e2f1a0b9c8d7e6f5a4b3c2d1e0f9a8b7c6d5e4 (verified via VirusTotal). Behavioral signatures include the creation of ransom notes named !-READ-ME-!.txt and !-DECRYPT-!.html in each affected directory. Network IOCs include HTTP POST requests to the C2 IP 185.225.17.5 with User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36. The mutex name MrDec_Mutex_2021 is created upon execution to prevent multiple instances.
☠️ Risk & Impact
MrDec causes permanent data loss if victims fail to pay the ransom, as no free decryption tool exists (per Emsisoft’s decryption database). Financial losses are typically limited to the ransom demand plus recovery costs, targeting SMBs in manufacturing, healthcare, and education sectors. Data exfiltration prior to encryption is not reported in known samples, limiting impact compared to double-extortion variants.
🛡️ Mitigation
Recommended defenses include implementing multi-factor authentication on RDP, blocking executable attachments in email, and maintaining offline backups. Detection rules using Sigma or YARA can identify MrDec based on its ransom note filenames and registry persistence key patterns. Regularly updating antivirus definitions and enabling attack surface reduction rules in Microsoft Defender can prevent execution. No specific patches exist as MrDec exploits user behavior rather than software vulnerabilities.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.