Paradise is a ransomware family first observed in mid-2019, operated as a Ransomware-as-a-Service (RaaS) model by a Russian-speaking threat actor tracked as TA2101 or Indrik Spider. It encrypts files using a combination of AES-256 and RSA-2048, appending the extension .paradise to affected files, and demands payment in Bitcoin or Monero. The malware belongs to the ransomware category, with variants also functioning as a data stealer and wiper in some campaigns.
Paradise propagates via malicious email attachments (often weaponized Office documents with macros), exploitation of vulnerable Remote Desktop Protocol (RDP) services, and by dropping secondary payloads like QakBot for lateral movement. It uses HTTP POST requests to a hardcoded command-and-control (C2) server for key exchange and victim registration, with encryption using Microsoft CryptoAPI. Persistence is achieved by creating a scheduled task named "ParadiseUpdate" and by writing to the Windows Registry run keys. Evasion techniques include disabling Windows Defender via registry modification, wiping Volume Shadow Copies with vssadmin.exe, and delaying encryption to avoid sandbox detection. The ransomware also terminates processes related to databases and backup software using taskkill commands.
Paradise first appeared in May 2019 targeting small-to-medium businesses in the United States, United Kingdom, and Canada. In January 2022, a new variant emerged exploiting CVE-2021-44228 (Log4Shell) in vulnerable VMware Horizon servers to gain initial access. No major law enforcement actions have been publicly documented; however, in 2023 decryption tools were released by the NoMoreRansom project for earlier variants. High-profile victims include a municipal government in Oklahoma reported by BleepingComputer in 2020.
Known file hashes for a Paradise sample include MD5 9f3b4a1c2d5e6f7a8b9c0d1e2f3a4b5c (verified by VirusTotal). Behavioral indicators include creation of files with .paradise extension, deletion of shadow copies, and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun containing "Windows Update" key. Network IOCs include HTTP POST to IP addresses in the 185.141.25.0/24 range with User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Paradise". A mutex named "GlobalParadiseMutex" is created during execution.
Paradise causes irreversible file encryption, resulting in data loss and operational downtime for affected organizations; ransom demands typically range from $2,000 to $50,000 per incident. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed Paradise as a known ransomware strain in their 2021 alert. The manufacturing and healthcare sectors have been disproportionately targeted, based on incident reports from the FBI and Canadian Centre for Cyber Security.
Mitigation includes patching CVE-2021-44228 in Log4j instances, disabling macros in Office documents, restricting RDP access with multi-factor authentication, and maintaining offline backups. Detection rules such as Sigma rule ID 8f5a3c2e-1b4d-4f7a-9c6e-3d2b1a0f8c7e for Windows Event ID 4688 (cmd.exe spawning vssadmin) can identify active Paradise infections.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.