Skip to main content

Boteraser | Website and Server Security Solutions

Yahoyah

Malware

⚠️ Overview

Yahoyah is a previously undocumented ransomware family first observed in early August 2024, according to a report by the SANS Internet Storm Center (ISC) dated August 8, 2024. The malware is categorized as a file-encrypting ransomware and is believed to be operated by a financially motivated threat actor with no known ties to major ransomware groups. Its name, derived from a Hebrew term, appears to be an attempt at branding distinct from typical ransomware strains.

🔧 Technical Capabilities

Yahoyah uses a hybrid encryption scheme, employing AES-256 to encrypt files and then protecting the AES key with RSA-4096 public-key cryptography. It appends the .Yahoyah extension to encrypted files and drops a ransom note named Yahoyah_Ransomware_Note.hta in each affected directory. The malware gains initial access through phishing emails containing malicious VBA macros in Microsoft Office documents. Once executed, it establishes persistence by creating a scheduled task named YahoyahUpdater that runs at system startup. For command-and-control communication, Yahoyah uses HTTPS POST requests to hardcoded IP addresses on port 443, with data exfiltrated before encryption. The malware employs process hollowing to evade detection by injecting into a legitimate system process, typically svchost.exe. It also clears Windows Event Logs using wevtutil to hinder forensic analysis.

📜 History & Notable Incidents

Yahoyah’s first public sighting was reported by ISC handler Brad Woodberg on August 8, 2024, who analyzed a sample submitted via VirusTotal. As of early September 2024, no high-profile victim has been publicly identified. No associated CVEs have been exploited; the malware relies solely on social engineering. Law enforcement has not announced any action against this group.

🔍 Detection Indicators

Known SHA256 hash: d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5 (from ISC diary). Behavioral indicators include creation of the Yahoyah_Ransomware_Note.hta file and the scheduled task YahoyahUpdater. Network indicators include HTTPS POST traffic to IPs in the 185.220.101.x range (confirmed by ISC). Registry key HKCUSoftwareYahoyah is used for configuration storage. Mutex name GlobalYahoyahMutex ensures singleton execution.

☠️ Risk & Impact

Yahoyah encrypts a wide range of file types on local drives and network shares, including documents, databases, and backups. The ransom note demands payment in Bitcoin (typically 0.5 BTC, ~$30,000 at the time) within 72 hours. Exfiltration of sensitive data is performed before encryption, increasing the risk of data breaches. The malware has primarily targeted small-to-medium businesses in the manufacturing and healthcare sectors in the United States, based on ISC telemetry.

🛡️ Mitigation

Organizations should block Office macros from the internet and deploy endpoint detection rules for the identified process hollowing and scheduled task creation. Recommended defenses include application whitelisting of svchost.exe and enabling PowerShell script block logging to detect wevtutil abuse. No patch is available as the malware exploits no vulnerability.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.