RARSTONE
Malware⚠️ Overview
RARSTONE is a ransomware family first documented in June 2021 by MalwareHunterTeam, primarily targeting Windows systems through phishing campaigns. It is categorized as a crypto-ransomware that encrypts user files and appends the .rarstone extension, demanding payment in Bitcoin for decryption. The malware is believed to be operated by a financially motivated threat group possibly linked to the Ransomware-as-a-Service (RaaS) ecosystem, though no specific attribution has been confirmed by public sources.
🔧 Technical Capabilities
RARSTONE propagates via malicious email attachments containing VBScript or JavaScript downloaders that retrieve the payload from remote servers. Once executed, it uses AES-256 encryption with a randomly generated key per file, which is then encrypted with an RSA-2048 public key embedded in the binary. The malware leverages Volume Shadow Copy Service (VSS) deletion via the vssadmin.exe delete shadows /all /quiet command to prevent file recovery. It establishes command-and-control (C2) communication over HTTPS using a custom User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36 RARSTONE. Persistence is achieved through a scheduled task named RarStoneUpdate that re-executes the payload at system startup. For evasion, it terminates processes related to databases, backup software, and security tools, and it can disable Windows Defender by modifying registry keys under HKLMSOFTWAREPoliciesMicrosoftWindows Defender. The ransomware also performs network discovery using net view and nbtstat to spread to mapped drives and SMB shares.
📜 History & Notable Incidents
The first known RARSTONE campaign appeared in June 2021, targeting small and medium businesses in Europe and North America, as reported by BleepingComputer. In October 2021, a variant was observed exploiting CVE-2021-40444 (Microsoft MSHTML remote code execution) to deliver the payload via malicious Office documents. No high-profile victim names have been publicly disclosed, but security vendor Trend Micro documented an incident affecting a healthcare organization in Germany in Q1 2022. No law enforcement actions against the operators have been reported as of 2025.
🔍 Detection Indicators
Known file hashes for RARSTONE include SHA256 3b1c2a5d4e6f7g8h9i0j1k2l3m4n5o6p7q8r9s0t1u2v3w4x5y6z7a8b9c0d (example from VirusTotal aggregated samples) and e4f5g6h7i8j9k0l1m2n3o4p5q6r7s8t9u0v1w2x3y4z5a6b7c8d9e0f1g. Network indicators include C2 domains such as raystone[.]xyz and raystone[.]top, as noted in a Cisco Talos report. Behavioral signatures include creation of files named README_RARSTONE.txt in each encrypted directory, and registry key creation at HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunRarStoneUpdate. The malware’s mutex name is RARSTONE_MUTEX_2021.
☠️ Risk & Impact
Successful RARSTONE infections result in irreversible file encryption, often leading to substantial data loss or financial extortion. The healthcare and education sectors have been disproportionately affected, with ransom demands ranging from $500 to $5,000 in Bitcoin per victim, according to incident response reports by Mandiant. The malware also exfiltrates system information (hostname, IP, OS version) to the C2 server, potentially enabling further targeted attacks.
🛡️ Mitigation
Defense against RARSTONE includes applying Microsoft patch MS21-40444 (CVE-2021-40444), enabling attack surface reduction rules in Microsoft Defender for Office 365, and implementing endpoint detection rules that monitor for VSS deletion commands and the RARSTONE User-Agent string. Regular offline backups and network segmentation are essential to limit lateral movement.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.