Void
Malware⚠️ Overview
Void, commonly referred to as VoidCrypt, is a ransomware family first observed in December 2021 by security researchers at SOC Prime and subsequently documented by Trend Micro. It is operated by financially motivated threat actors who distribute the malware through phishing campaigns and exploit kits. VoidCrypt belongs to the ransomware category, specifically a file-encrypting trojan that demands a ransom for decryption.
🔧 Technical Capabilities
VoidCrypt propagates via malicious email attachments, often masquerading as invoices or shipment notifications, and uses exploitation of unpatched vulnerabilities such as CVE-2021-40444 (MSHTML remote code execution) to gain initial access. Once executed, it establishes persistence by adding a registry run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun with the value name "VoidCrypt". The ransomware employs a hybrid encryption scheme using RSA-2048 and AES-256 to encrypt files, appending the extension ".[].Void" to affected files. It deletes Volume Shadow Copies via vssadmin.exe and disables Windows Defender using PowerShell commands to evade detection. C2 communication uses HTTP POST requests to hardcoded IP addresses, often hosted on bulletproof hosting providers in Eastern Europe.
📜 History & Notable Incidents
VoidCrypt first appeared in December 2021 with campaigns targeting small and medium businesses in the United States and India. In February 2022, a variant known as VoidCrypt 2.0 was analyzed by BleepingComputer, which noted the use of a unique ransom note named "README.html" containing a Tor payment site. No high-profile victims or law enforcement takedowns have been publicly reported as of 2025.
🔍 Detection Indicators
Known file hashes for VoidCrypt include SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample from MalwareBazaar) and behavioral signatures such as creation of mutex "VoidCryptMutex". Network IOCs include HTTP requests to domains like "voidcrypt[.]top" and User-Agent strings "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36". Registry artifacts include the key HKCUSoftwareVoidCrypt storing encryption state.
☠️ Risk & Impact
VoidCrypt causes permanent data loss if victims fail to pay the ransom, typically demanded in Bitcoin ranging from $500 to $5,000. The malware exfiltrates a small sample of files before encryption to prove possession. Affected sectors include healthcare, manufacturing, and legal services, as reported by Trend Micro in a 2022 threat advisory.
🛡️ Mitigation
Recommended defenses include blocking the execution of vssadmin.exe and PowerShell from untrusted sources, deploying EDR solutions with behavioral detection rules for registry modifications, and maintaining offline backups. Microsoft recommends enabling Tamper Protection in Defender for Endpoint and applying patches for CVE-2021-40444. MITRE ATT&CK techniques used include T1059.001 (PowerShell), T1486 (Data Encrypted for Impact), and T1490 (Inhibit System Recovery).
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.