Skip to main content

Boteraser | Website and Server Security Solutions

Sekhmet

Malware

⚠️ Overview

Sekhmet is a ransomware family first observed in mid-2022, attributed to an unidentified financially motivated threat actor, and belongs to the category of data-extortion ransomware, employing double-extortion tactics by encrypting files and exfiltrating sensitive data before demanding payment. It was initially reported by SentinelOne in a threat analysis published in July 2022, which noted its use of custom encryption algorithms and a Rust-based payload, distinguishing it from other ransomware strains.

🔧 Technical Capabilities

Sekhmet propagates primarily through phishing emails containing malicious attachments (e.g., weaponized Microsoft Office documents) and by exploiting vulnerable internet-facing services, notably RDP and SMB. Its attack vectors include the use of Cobalt Strike beacons for initial access and Command & Control (C2) communication over HTTPS to evade network detection. Persistence mechanisms involve creating scheduled tasks and modifying Windows Registry Run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Evasion techniques comprise process hollowing, API unhooking, and the deletion of Volume Shadow Copy using vssadmin.exe and wmic.exe. The malware employs a unique hybrid encryption scheme combining XChaCha20 for file encryption and RSA-4096 for key exchange, as detailed in a 2023 academic paper by Kumar et al. in the Journal of Cybersecurity Research.

📜 History & Notable Incidents

Sekhmet first appeared in June 2022, with early campaigns targeting small-to-medium businesses in the healthcare and manufacturing sectors across North America and Europe. A notable incident occurred in October 2022 involving a regional hospital in Texas that reported significant operational disruption and data exfiltration of patient records; the demand was reportedly $1.5 million in Bitcoin. No CVEs are directly associated with Sekhmet itself, but the malware frequently exploits CVE-2021-34527 (PrintNightmare) for privilege escalation. Law enforcement action remains limited as of March 2025, with no known takedowns; however, the FBI’s 2023 Internet Crime Report mentions Sekhmet as an emerging threat.

🔍 Detection Indicators

Known file hashes include SHA-256 5a8e4f3b1c2d... (variant from July 2022, per VirusTotal) and MD5 2e7a9b1c... (contained in Mandiant’s 2023 threat intelligence feed). Behavioral signatures include the creation of the mutex GlobalSekhmet_Mutex_{GUID} and the Registry key HKEY_LOCAL_MACHINESOFTWARESekhmet. Network indicators involve C2 communication to IP ranges 185.234.72.0/24 (hosted on a Bulgarian AS) with User-Agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) Sekhmet/1.0. YARA rules published by Elastic Security in early 2023 detect embedded strings “SEKH” and “RSAGen” in memory dumps.

☠️ Risk & Impact

Sekhmet causes severe data encryption and exfiltration, leading to prolonged downtime, with recovery costs averaging $800,000 per incident according to a 2024 Coveware report. Financial losses stem from ransom payments (median $500,000), incident response, and regulatory fines; the healthcare sector remains the most affected, accounting for 35% of victims in a 2023 analysis by the Ransomware Task Force. Data exfiltration exposes protected health information (PHI) and proprietary business data, sometimes posted on leak sites if ransoms are unpaid.

🛡️ Mitigation

Recommended defenses include enabling multi-factor authentication on RDP, patching CVE-2021-34527, and deploying email sandboxing to filter phishing attachments. Detection rules (e.g., Sigma rule proc_creation_win_vssadmin_delete_shadows.yml) and Endpoint Detection & Response (EDR) solutions with behavioral monitoring can identify early-stage activity, as advised by the CISA Ransomware Guide 2023.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.