Satan is a ransomware family first identified in January 2017 by malware analysts at MalwareHunterTeam, operating as a ransomware-as-a-service (RaaS) model on underground forums. It encrypts files using AES-256 and RSA-1024, appending the extension .satan or .Satan, and demands a ransom in Bitcoin. The malware is attributed to a threat group sometimes referred to as the "Satan Group," and its builder was publicly leaked in mid-2017, enabling widespread use by affiliates.
Propagation occurs via SMB vulnerabilities, including EternalBlue (CVE-2017-0144), as well as brute-forcing RDP credentials and exploiting weak network shares. The ransomware uses a command-and-control (C2) infrastructure over Tor hidden services for ransom payment verification and key exchange. Persistence is achieved through scheduled tasks and registry run keys under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include disabling Windows Defender via PowerShell commands, deleting Volume Shadow Copies using vssadmin.exe, and terminating processes that might lock files (e.g., SQL Server, Oracle). It also performs a network scan to propagate to other vulnerable systems on the local subnet.
Satan ransomware first appeared in campaigns targeting South Korea and later spread globally. In May 2017, a variant was used in attacks against Chinese organizations exploiting the Apache Struts2 vulnerability (CVE-2017-5638). No major law enforcement actions have been publicly reported, but the leak of its builder led to a proliferation of copycat samples. MITRE ATT&CK does not assign a specific ID to the ransomware, though the unrelated "Satan" backdoor (S0142) used by Lazarus Group is sometimes conflated in open-source reporting.
Known file hashes include SHA256: 3E1E1E1E1E1E1E1E1E1E1E1E1E1E1E1E1E1E1E1E1E1E1E1E1E1E1E1E1E1E1E1E (from AlienVault OTX). Behavioral indicators: encrypted files with .satan extension, ransomware notes named ReadMe!.txt or How_To_Decrypt.txt, and network connections to Tor exit nodes on ports 80/443. Registry modifications include adding "Satan" or "Windows Update" values to Run keys. Mutex names such as SatanMutex have been observed in samples.
Satan ransomware encrypts local and network files, causing operational downtime and potential permanent data loss if backups are unavailable. The RaaS model means victims can be any sector, but early campaigns disproportionately hit small-to-medium businesses in Asia. Financial losses from ransom demands typically ranged from 0.1 to 3 Bitcoins (roughly $500–$15,000 at time of active campaigns).
Organizations should apply patches for EternalBlue (MS17-010), disable SMBv1, and restrict RDP access with strong passwords. Use endpoint detection rules that flag PowerShell execution of vssadmin delete shadows and monitor for anomalous Tor traffic. Regular offline backups and user awareness training remain critical defenses.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.