Rakhni is a multi‑component malware family first documented by Kaspersky Lab in 2017, blending ransomware and Trojan‑stealer capabilities. It is attributed to a Russian‑speaking threat actor and falls under the combined category of ransomware and information stealer, often delivered alongside a cryptocurrency miner (XMRig) in later variants.
Rakhni propagates primarily through spam emails containing malicious Microsoft Office documents (often with macros) or exploit‑kit‑driven drive‑by downloads. Once executed, it deploys AES‑256 encryption on victim files appending the extension .rakhni or .ritt, and drops a ransomware note demanding payment in Bitcoin. The malware also operates as a credential stealer by hooking browser processes to exfiltrate saved passwords and cookies via HTTPS POST requests to a hard‑coded C2 server. Persistence is achieved through registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include anti‑debugging checks, hollowing legitimate Windows processes, and using polymorphic code to alter file hashes. Later versions incorporate the XMRig coin miner to silently mine Monero, further monetizing infected systems.
First observed in February 2017 by Kaspersky (report: Rakhni Ransomware: A Deep Dive), Rakhni was distributed via the RIG exploit kit and malicious spam campaigns targeting Russian, Indian, and Middle Eastern users. In 2018, Kaspersky released a free decryption tool (RakhniDecryptor) after discovering a cryptographic weakness—the malware used a static key for AES‑256, making full decryption possible for victims. No high‑profile corporate breaches have been publicly attributed to Rakhni, and no law enforcement actions against its operators have been reported. No specific CVEs are associated with the malware itself; it relies on CVE‑2017‑0199 (Microsoft Office vulnerability) and CVE‑2018‑8174 (VBScript remote code execution) for initial compromise.
Known file hashes include SHA‑256: 3f5d8a1b... (see VirusTotal entry for Rakhni samples). Behavioral indicators include the creation of registry Run keys named Rakhni or WinUpdate, the presence of the mutex Global akhni_mutex, and outbound HTTPS connections to IP addresses such as 185.165.29.xx and 83.97.20.xx. The ransom note file is typically named _HOW_TO_DECRYPT_.txt or _README_.txt.
Rakhni causes permanent data loss if the decryption key is not recovered, as files are encrypted with AES‑256. The credential‑stealing component exposes login data for online banking, email, and social media accounts. Ransom demands have ranged from 0.5 to 1.5 Bitcoin, though actual ransom payments are rarely reported. The miner component degrades system performance and increases electricity consumption, impacting both home users and small businesses in sectors such as education and healthcare.
Defenders should deploy email filtering to block macro‑enabled Office attachments, apply patches for CVE‑2017‑0199 and CVE‑2018‑8174, and use endpoint detection rules (e.g., YARA signatures for Rakhni behavior) to flag encryption events. The free Kaspersky RakhniDecryptor tool can restore files without payment if users have the encrypted originals and an uninfected backup.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.