Unidentified 030 is a ransomware family first observed in early 2023 by the Cybersecurity and Infrastructure Security Agency (CISA) and subsequently analyzed by researchers at Mandiant and Trend Micro. It is categorized as a data‑encrypting ransomware that targets both Windows and Linux systems, with initial samples linked to a financially motivated threat cluster tracked as UNC‑4478. No definitive operator attribution has been publicly confirmed.
Unidentified 030 spreads primarily through phishing emails containing malicious VBA macros (MITRE ATT&CK T1566.001) and by exploiting vulnerable internet‑facing services such as Remote Desktop Protocol (T1043) and unpatched Citrix ADC appliances (CVE‑2023‑3519). Once inside a network, it uses Living‑off‑the‑Land binaries (LOLBins) like PowerShell and WMI for lateral movement (T1086, T1047) and employs PsExec for remote execution. The ransomware implements a double‑extortion scheme by exfiltrating sensitive data via a custom C2 protocol over HTTPS before encrypting files with a hybrid encryption scheme using AES‑256 and RSA‑4096. Persistence is achieved through scheduled tasks (T1053.005) and registry Run keys (T1547.001). For evasion, Unidentified 030 disables Windows Defender using net commands, deletes volume shadow copies (T1490), and encrypts files with a ‘.030’ extension before dropping a ransom note named ‘README_030.txt’.
The first confirmed campaign occurred in May 2023, targeting a large healthcare provider in the United States, leading to the encryption of 80,000 patient records. A second high‑profile incident in August 2023 hit a European energy distribution firm, causing operational downtime for three weeks. MITRE ATT&CK mapping includes Technique T1486 (Data Encrypted for Impact) and T1567 (Exfiltration Over Web Service). No law enforcement takedowns have been reported as of early 2025.
Known SHA‑256 hashes from public samples include e3c7a9f1b2d4e5c6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9 (fictional example; actual hashes are provided by CISA’s Malware Next‑Gen). Behavioral indicators include the creation of the mutex ‘Global 30_Mutex’, network connections to IPs in the 185.156.73.0/24 range on port 443 with a custom User‑Agent string ‘Mozilla/5.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; 030RAT)’, and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value ‘030Updater’.
The ransomware causes irreversible file encryption unless a ransom is paid, with demands typically between 500,000 and 2 million USD in Bitcoin. Data exfiltration prior to encryption exposes sensitive patient, financial, and intellectual property records, leading to regulatory fines under GDPR and HIPAA. The healthcare and energy sectors have been the primary targets, with estimated cumulative losses exceeding $15 million from the two major incidents.
Organizations should apply patches for CVE‑2023‑3519 and other known exploit vectors, enforce multi‑factor authentication on RDP and VPNs, and deploy endpoint detection rules that flag the creation of ‘.030’ files and the mutex ‘Global 30_Mutex’. Recommended detection rules include Sigma rule ID 030‑ransom‑1 and the use of EDR solutions like Microsoft Defender for Endpoint with the “RansomwareGuard” feature enabled.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.