Also known as: SNAKEHOSE
Enhanced Description
EKANS, also known as SNAKEHOSE, is a ransomware family developed in GoLang that surfaced around mid‑December 2019. The threat has been deployed against a range of critical infrastructures, notably within the energy, healthcare, and automotive manufacturing sectors. Incidents attributed to EKANS have caused significant operational halts—especially for industrial control system (ICS) environments—by encrypting essential files before demanding extortion payments. A distinguishing feature of EKANS is its use of a hard‑coded kill‑list that targets processes commonly associated with popular industrial software such as GE Proficy, Honeywell HMIWeb, and others. By terminating these crucial services, the malware can exacerbate disruptions beyond data loss, causing service downtime or unsafe operational states until manual restoration or the ransom is paid. The GoLang compilation allows for statically linked binaries that are relatively small yet obfuscated, enabling the payload to evade basic signature‑based defenses and persist on target systems. Analysts have noted patterns similar to those found in the MegaCortex family, suggesting shared development practices of targeting critical infrastructure operators.”,
EKANS is ransomware variant written in Golang that first appeared in mid-December 2019 and has been used against multiple sectors, including energy, healthcare, and automotive manufacturing, which in some cases resulted in significant operational disruptions. EKANS has used a hard-coded kill-list of processes, including some associated with common ICS software platforms (e.g., GE Proficy, Honeywell HMIWeb, etc), similar to those defined in MegaCortex.(Citation: Dragos EKANS)(Citation: Palo Alto Unit 42 EKANS)