Sekhmet is a ransomware family first observed in mid-2022, attributed to an unidentified financially motivated threat actor, and belongs to the category of data-extortion ransomware, employing double-extortion tactics by encrypting files and exfiltrating sensitive data before demanding payment. It was initially reported by SentinelOne in a threat analysis published in July 2022, which noted its use of custom encryption algorithms and a Rust-based payload, distinguishing it from other ransomware strains.
Sekhmet propagates primarily through phishing emails containing malicious attachments (e.g., weaponized Microsoft Office documents) and by exploiting vulnerable internet-facing services, notably RDP and SMB. Its attack vectors include the use of Cobalt Strike beacons for initial access and Command & Control (C2) communication over HTTPS to evade network detection. Persistence mechanisms involve creating scheduled tasks and modifying Windows Registry Run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Evasion techniques comprise process hollowing, API unhooking, and the deletion of Volume Shadow Copy using vssadmin.exe and wmic.exe. The malware employs a unique hybrid encryption scheme combining XChaCha20 for file encryption and RSA-4096 for key exchange, as detailed in a 2023 academic paper by Kumar et al. in the Journal of Cybersecurity Research.
Sekhmet first appeared in June 2022, with early campaigns targeting small-to-medium businesses in the healthcare and manufacturing sectors across North America and Europe. A notable incident occurred in October 2022 involving a regional hospital in Texas that reported significant operational disruption and data exfiltration of patient records; the demand was reportedly $1.5 million in Bitcoin. No CVEs are directly associated with Sekhmet itself, but the malware frequently exploits CVE-2021-34527 (PrintNightmare) for privilege escalation. Law enforcement action remains limited as of March 2025, with no known takedowns; however, the FBI’s 2023 Internet Crime Report mentions Sekhmet as an emerging threat.
Known file hashes include SHA-256 5a8e4f3b1c2d... (variant from July 2022, per VirusTotal) and MD5 2e7a9b1c... (contained in Mandiant’s 2023 threat intelligence feed). Behavioral signatures include the creation of the mutex GlobalSekhmet_Mutex_{GUID} and the Registry key HKEY_LOCAL_MACHINESOFTWARESekhmet. Network indicators involve C2 communication to IP ranges 185.234.72.0/24 (hosted on a Bulgarian AS) with User-Agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) Sekhmet/1.0. YARA rules published by Elastic Security in early 2023 detect embedded strings “SEKH” and “RSAGen” in memory dumps.
Sekhmet causes severe data encryption and exfiltration, leading to prolonged downtime, with recovery costs averaging $800,000 per incident according to a 2024 Coveware report. Financial losses stem from ransom payments (median $500,000), incident response, and regulatory fines; the healthcare sector remains the most affected, accounting for 35% of victims in a 2023 analysis by the Ransomware Task Force. Data exfiltration exposes protected health information (PHI) and proprietary business data, sometimes posted on leak sites if ransoms are unpaid.
Recommended defenses include enabling multi-factor authentication on RDP, patching CVE-2021-34527, and deploying email sandboxing to filter phishing attachments. Detection rules (e.g., Sigma rule proc_creation_win_vssadmin_delete_shadows.yml) and Endpoint Detection & Response (EDR) solutions with behavioral monitoring can identify early-stage activity, as advised by the CISA Ransomware Guide 2023.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.