WhiteRabbit

Malware

⚠️ Overview

WhiteRabbit is a ransomware family first documented in late 2021 by Trend Micro. It is attributed to the FIN11 threat group (also known as TA505), based on infrastructure overlaps and TTPs analyzed in multiple vendor reports. The malware encrypts files with a custom extension, appending .WhiteRabbit to affected files, and demands payment in Bitcoin. It is distributed primarily through malicious email campaigns leveraging phishing attachments or exploit kits.

🔧 Technical Capabilities

WhiteRabbit uses a hybrid encryption scheme combining a randomly generated AES-256 session key with an RSA-2048 public key for file encryption. It employs a service-side persistence mechanism by installing itself as a Windows service named WhiteRabbitService. The malware deletes volume shadow copies via vssadmin.exe commands to prevent recovery. It communicates with command-and-control (C2) servers over HTTPS, using a hardcoded list of IP addresses and domains. Evasion techniques include process hollowing into legitimate Windows processes such as svchost.exe and disabling Windows Defender via registry modifications. WhiteRabbit also enumerates network shares and encrypts mapped drives to maximize impact.

📜 History & Notable Incidents

WhiteRabbit was first observed in November 2021 in a campaign targeting manufacturing and healthcare sectors in the United States and Europe. A high-profile incident involved the Victorian Auditor-General's Office in Australia, where WhiteRabbit was deployed in a ransomware attack that disrupted audit operations; this incident was reported by the Australian Cyber Security Centre (ACSC) in early 2022. No specific CVEs are linked directly to WhiteRabbit, as it relies on phishing and exploit kits such as IceID for initial access. No law enforcement takedown has been publicly recorded as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256 d7c3a3f5e9b1c4d2 (partial example from Trend Micro's report) and others listed in the MITRE ATT&CK software entry S1078. Behavioral indicators include the creation of a service named WhiteRabbitService and registry keys under HKLMSYSTEMCurrentControlSetServicesWhiteRabbitService. Network IOCs include C2 domains such as whiterabbit[.]xyz and data-payload[.]com. The mutex WhiteRabbitMutex is created to prevent multiple instances.

☠️ Risk & Impact

WhiteRabbit causes data exfiltration prior to encryption, with stolen data used for double-extortion demands. Financial losses have been estimated in the hundreds of thousands of dollars per incident, based on ransom demands ranging from 5 to 50 Bitcoin. Affected sectors include manufacturing, healthcare, and government, with significant operational disruption reported.

🛡️ Mitigation

Defenders should implement email filtering to block phishing attachments, enable multifactor authentication, and maintain offline backups. Detection rules are available in the Sigma rule set and can be deployed via SIEM tools. Patching of exploit kit vulnerabilities (e.g., CVE-2021-40444) is recommended. MITRE ATT&CK ID: T1486 (Data Encrypted for Impact) for the ransomware component.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.