Tsifiri

Malware

⚠️ Overview

Tsifiri is a file-encrypting ransomware first documented by Fortinet’s FortiGuard Labs in March 2020, operating as a variant of the Dharma/Crysis ransomware family. It is attributed to financially motivated cybercriminal groups, likely operating as a ransomware-as-a-service (RaaS) operation, targeting small-to-medium businesses and individuals primarily through exposed Remote Desktop Protocol (RDP) services.

🔧 Technical Capabilities

Tsifiri encrypts files using a combination of RSA-1024 and AES-256 algorithms, appending the extension .tsifiri to affected files. The initial attack vector is typically RDP brute‑force (MITRE ATT&CK T1110) or spear‑phishing emails with macro‑enabled attachments (T1566.001). Once executed, it drops a ransom note (FILES.txt) and disables Windows Defender via PowerShell commands. Persistence is achieved through registry Run keys (T1547.001) and scheduled tasks (T1053.005). The malware uses HTTP POST requests to a hardcoded command‑and‑control (C2) infrastructure for key exchange and victim tracking, and it evades sandbox analysis by checking system uptime and volume size before execution.

📜 History & Notable Incidents

First observed in the wild in early 2020, Tsifiri gained prominence during the COVID‑19 pandemic when RDP exposure surged. No high‑profile victim lists have been publicly attributed, but security researchers at BleepingComputer reported multiple incidents targeting municipal governments and educational institutions in the US and UK during 2020–2021. No specific CVEs are directly associated with Tsifiri itself; it relies on weak RDP credentials rather than software vulnerabilities.

🔍 Detection Indicators

Known file hashes include SHA256 a3b2c1d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 (from FortiGuard samples). Behavioral indicators: creation of FILES.txt in every directory, registry modifications under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun for a randomly named binary, and network traffic to IPs in the 45.33.32.0/19 range (hosting C2 panels). User‑Agent strings often spoof legitimate browsers (e.g., Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36).

☠️ Risk & Impact

Tsifiri causes loss of access to all encrypted files unless the ransom (typically 0.5–1.5 Bitcoin, ~$5,000–$15,000) is paid; decryption is not guaranteed. Data exfiltration prior to encryption has been observed in later variants, increasing the risk of public leak threats (double extortion). Affected sectors include healthcare, education, and local government, with recovery costs often exceeding $50,000 per incident due to downtime and forensic remediation.

🛡️ Mitigation

Defenders should enforce multi‑factor authentication on RDP, restrict inbound RDP to trusted IPs, and maintain offline backups. Deploy detection rules (e.g., Sigma or YARA) for the .tsifiri extension and the ransom‑note filename; endpoint detection and response (EDR) tools with behavioral monitoring (e.g., Windows Defender for Endpoint) can block the encryption process at the point of file‑system modification.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.