Skip to main content

Boteraser | Website and Server Security Solutions

Rakhni

Malware

⚠️ Overview

Rakhni is a multi‑component malware family first documented by Kaspersky Lab in 2017, blending ransomware and Trojan‑stealer capabilities. It is attributed to a Russian‑speaking threat actor and falls under the combined category of ransomware and information stealer, often delivered alongside a cryptocurrency miner (XMRig) in later variants.

🔧 Technical Capabilities

Rakhni propagates primarily through spam emails containing malicious Microsoft Office documents (often with macros) or exploit‑kit‑driven drive‑by downloads. Once executed, it deploys AES‑256 encryption on victim files appending the extension .rakhni or .ritt, and drops a ransomware note demanding payment in Bitcoin. The malware also operates as a credential stealer by hooking browser processes to exfiltrate saved passwords and cookies via HTTPS POST requests to a hard‑coded C2 server. Persistence is achieved through registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include anti‑debugging checks, hollowing legitimate Windows processes, and using polymorphic code to alter file hashes. Later versions incorporate the XMRig coin miner to silently mine Monero, further monetizing infected systems.

📜 History & Notable Incidents

First observed in February 2017 by Kaspersky (report: Rakhni Ransomware: A Deep Dive), Rakhni was distributed via the RIG exploit kit and malicious spam campaigns targeting Russian, Indian, and Middle Eastern users. In 2018, Kaspersky released a free decryption tool (RakhniDecryptor) after discovering a cryptographic weakness—the malware used a static key for AES‑256, making full decryption possible for victims. No high‑profile corporate breaches have been publicly attributed to Rakhni, and no law enforcement actions against its operators have been reported. No specific CVEs are associated with the malware itself; it relies on CVE‑2017‑0199 (Microsoft Office vulnerability) and CVE‑2018‑8174 (VBScript remote code execution) for initial compromise.

🔍 Detection Indicators

Known file hashes include SHA‑256: 3f5d8a1b... (see VirusTotal entry for Rakhni samples). Behavioral indicators include the creation of registry Run keys named Rakhni or WinUpdate, the presence of the mutex Global akhni_mutex, and outbound HTTPS connections to IP addresses such as 185.165.29.xx and 83.97.20.xx. The ransom note file is typically named _HOW_TO_DECRYPT_.txt or _README_.txt.

☠️ Risk & Impact

Rakhni causes permanent data loss if the decryption key is not recovered, as files are encrypted with AES‑256. The credential‑stealing component exposes login data for online banking, email, and social media accounts. Ransom demands have ranged from 0.5 to 1.5 Bitcoin, though actual ransom payments are rarely reported. The miner component degrades system performance and increases electricity consumption, impacting both home users and small businesses in sectors such as education and healthcare.

🛡️ Mitigation

Defenders should deploy email filtering to block macro‑enabled Office attachments, apply patches for CVE‑2017‑0199 and CVE‑2018‑8174, and use endpoint detection rules (e.g., YARA signatures for Rakhni behavior) to flag encryption events. The free Kaspersky RakhniDecryptor tool can restore files without payment if users have the encrypted originals and an uninfected backup.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.