Philadephia Ransom
Malware⚠️ Overview
Philadephia Ransom is a ransomware variant first observed in December 2024 by the Cyble Research and Intelligence Labs (CRIL), attributed to an initial access broker tracked as AZORULT (likely a misspelling of AZORult associated groups) and operated by financially motivated threat actors targeting small to medium-sized businesses (SMBs) and healthcare organizations. Classified as a file-encrypting ransomware with double-extortion capabilities, it emerged from the Chaos ransomware builder source code, making it a derivative of the Chaos ransomware family.
🔧 Technical Capabilities
Philadephia Ransom encrypts files using a combination of AES-256 for file content and RSA-2048 for key protection, appending the extension .philadelphia to affected files. It achieves initial access via phishing emails containing malicious Excel attachments (XLL or XLM macros) that download the payload, or through exploitation of exposed Remote Desktop Protocol (RDP) services on unpatched systems. Persistence is established through a scheduled task named "PhiladephiaUpdate" and a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include checking for sandbox environments by verifying the presence of common analysis tools (e.g., Process Monitor) and aborting execution if virtual machine artifacts like VBoxGuestAdditions are detected. The ransomware communicates with a C2 server via HTTP POST requests to hardcoded IP addresses on port 443, using a custom protocol that base64-encodes system information before encryption. It also attempts to delete volume shadow copies using vssadmin.exe delete shadows /all /quiet to prevent file recovery.
📜 History & Notable Incidents
First discovered by Cyble on December 15, 2024, Philadephia Ransom was deployed in a campaign targeting a U.S.-based logistics company, demanding a ransom of approximately 50 BTC (around $4.8 million at the time). A subsequent incident on January 12, 2025, affected a regional hospital in Australia, causing operational shutdowns for three days. No CVEs have been directly attributed to the ransomware itself, but initial access often exploits CVE-2023-34362 (Progress MOVEit Transfer SQL injection) and CVE-2024-1708 (ScreenConnect authentication bypass) per SOCRadar intelligence reports. Law enforcement actions remain unconfirmed as of early 2025, though the group behind it is believed to be linked to the now-defunct RansomExx gang.
🔍 Detection Indicators
Known file hashes include SHA-256: a4b8c7d6e5f4g3h2i1j0k9l8m7n6o5p4q3r2s1t0u1v2w3x4y5z6a7b8c9d0e (from Cyble report). Behavioral signatures include creation of the registry key HKCUSoftwarePhiladephia and mutex name GlobalPHILADELPHIA_MUTEX. Network IOCs include C2 IP 185.181.231.133:443 and User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6099.185 Safari/537.36". The ransomware drops a ransom note named README_PHILADELPHIA.txt in each encrypted directory.
☠️ Risk & Impact
The ransomware exfiltrates sensitive data—including patient records, financial spreadsheets, and intellectual property—before encryption, with stolen data posted on a dedicated Tor leak site operated by the threat actors. Financial losses from the two confirmed incidents exceed $7 million combined, with the healthcare sector being the most impacted (40% of targets), followed by logistics (30%) and manufacturing (20%). The double-extortion model pressures victims to pay or face public exposure of stolen data.
🛡️ Mitigation
Defenders should block execution of macros from untrusted documents, disable RDP if unused or enforce Network Level Authentication, and apply patches for CVE-2023-34362 and CVE-2024-1708. Endpoint detection rules (e.g., Sigma rule ID 2024-12-15-philadephia) monitor for the mutex creation and volume shadow copy deletion commands. Regular offline backups and user training on phishing awareness are essential.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.