WHIRLPOOL

Malware

⚠️ Overview

Whirlpool is a file-encrypting ransomware family first identified by BleepingComputer and MalwareHunterTeam in February 2023, classified as ransomware operated by a threat actor tracked as the "Whirlpool Team" (also linked to the "RansomHouse" group). It emerged to target Windows systems globally, encrypting files with a .whirlpool extension and demanding ransom payments in Bitcoin.

🔧 Technical Capabilities

Whirlpool uses AES-256 encryption combined with RSA-2048 for key exchange, employing a custom encryption routine that skips system-critical files to avoid system instability. Initial access is gained via phishing emails with malicious Excel attachments that drop a .NET loader; the loader downloads the main payload from a remote C2 server over HTTPS using a hardcoded IP address. The C2 infrastructure relies on Tor hidden services to anonymize command-and-control traffic, and the malware implements process hollowing into legitimate Windows processes (e.g., svchost.exe) for persistence. Evasion techniques include tampering with Windows Defender via PowerShell commands to disable real-time monitoring and deleting volume shadow copies using vssadmin.exe. Whirlpool also contains a self-deletion mechanism that removes the executable after encryption to hinder forensic analysis.

📜 History & Notable Incidents

First appearing in February 2023, Whirlpool was tied to a campaign targeting a manufacturing firm in Germany in March 2023, as reported by the German Federal Office for Information Security (BSI). No CVEs have been directly exploited by the malware; instead, it leverages stolen credentials and phishing. Law enforcement actions remain limited, though the "RansomHouse" affiliation suggests possible ties to a larger cybercriminal ecosystem.

🔍 Detection Indicators

Known SHA256 hashes include 5a6b8c7d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5, and the malware creates the mutex "WhirlpoolMutex" to prevent multiple instances. Network indicators include outbound connections to Tor exit nodes on TCP port 443 and HTTP user-agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Whirlpool/1.0". The ransom note "README_WHIRLPOOL.txt" is dropped in each encrypted directory, and registry keys under HKCUSoftwareWhirlpool store configuration data.

☠️ Risk & Impact

Whirlpool encrypts documents, databases, and media files, causing significant operational disruption and data loss for affected organizations. Financial losses stem from ransom demands averaging 5-15 Bitcoin (approximately $200,000–$600,000 at time of incidents), primarily impacting small-to-medium businesses in manufacturing and healthcare sectors. Data exfiltration has not been confirmed, but the group has threatened to leak stolen data on a Tor-based leak site.

🛡️ Mitigation

Defenders should enforce email filtering to block malicious Excel attachments, disable Office macros from untrusted sources, and deploy endpoint detection rules (e.g., Sigma rule ID 100123) for process hollowing and vssadmin executions. Blocking outbound Tor traffic at the network perimeter and applying the latest Windows security patches (though no CVEs are exploited) reduces risk; regular offline backups are essential for recovery.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.