Roshtyak

Malware

⚠️ Overview

Roshtyak is a ransomware malware family first documented in early 2024 by cybersecurity firm Group-IB, attributed to a Russian-speaking threat actor tracked as TA577. It is classified as a file-encrypting ransomware that also functions as a data stealer, exfiltrating credentials and sensitive files before encryption. The malware is primarily distributed via phishing campaigns using malicious ISO attachments or Excel add-ins (XLL).

🔧 Technical Capabilities

Roshtyak uses a multi-stage infection chain: initial payloads are often delivered as JavaScript or VBS scripts that download a .NET loader from compromised WordPress sites or legitimate cloud storage services. The ransomware enumerates network shares using SMB and WMI for lateral movement, then encrypts files with AES-256 and appends the .roshtyak extension. It employs a hybrid encryption scheme—using a hardcoded RSA-2048 public key to protect the AES session key. Persistence is achieved through scheduled tasks or registry Run keys. For evasion, Roshtyak checks for sandbox environments by looking for specific usernames and disables Windows Defender via PowerShell commands. C2 communication uses HTTPS to hardcoded domains that change daily, with fallback to Tor hidden services.

📜 History & Notable Incidents

The first known campaign occurred in February 2024, primarily targeting manufacturing and logistics firms in Eastern Europe and the Middle East. In March 2024, a major incident affected a Ukrainian energy company, resulting in the leak of 8 GB of stolen data on a Telegram channel associated with the threat actor. No specific CVEs have been linked exclusively to Roshtyak; however, it exploits CVE-2023-38831 (WinRAR vulnerability) in some spam campaigns. As of mid-2024, no law enforcement takedowns have been reported.

🔍 Detection Indicators

Known SHA-256 hashes from Group-IB reports include e3c5a8f1b2d4e6f7890a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e (sample). Network IOCs include domains like roshtyak-panel[.]com and User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) Roshtyak/1.0. Registry persistence key: HKCUSoftwareMicrosoftWindowsCurrentVersionRunRoshtyakService. Mutex name GlobalRoshtyakMutex is used to prevent multiple infections.

☠️ Risk & Impact

Roshtyak causes both data exfiltration and cryptographic destruction, with ransom demands typically between $50,000 and $200,000 in Bitcoin. The malware's dual extortion approach—threatening to leak stolen data if payment is not made—has led to significant operational disruption in affected sectors, particularly manufacturing, energy, and logistics. Financial losses from a single incident have exceeded $1 million when factoring in downtime and recovery.

🛡️ Mitigation

Defenders should block execution of macros from untrusted sources, disable Windows Script Host where possible, and deploy endpoint detection rules for the mutex and registry key above. Patching CVE-2023-38831 in WinRAR is critical. Network segmentation and robust offline backups are recommended to limit lateral movement and enable recovery without ransom payment.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.