Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors goddamn ransomwhere

goddamn ransomwhere

TLP:CLEAR
Active

Also known as: tracked as, Bjorka, SkyWave, quic, Colddraw Ransomware, built a, OffSec, Lolkek, medium-sized, medium-sized bu, targeting nume, Dispossessor, active since August 2023, RA World, Raznatovic, Linux VMware, 54BB47h, Fonix, Abyss Locker, ARCrypter, GlobeImposter, CosmicBeetle, PlayCrypt, N13V, operated by UNC2190, FonixCrypter

Description

goddamn ransomwhere represents a modern ransomware-as-a-service operation that blends traditional cryptographic techniques with contemporary operational tactics. The malware encrypts each file individually using AES‑256‑CBC in conjunction with an RSA‑2048 key wrapped within the TLS‑style PKCS#1 v1.5 envelope, ensuring that decryption is only possible through the attacker’s key‑management infrastructure. Deployment typically occurs via spearphishing emails carrying malicious attachments or direct downloads from compromised sites; once executed, it establishes persistence by creating a Windows Service with a randomly generated name in %ProgramData% and spawns a scheduled task to run on user logon via schtasks.exe. The actor additionally targets virtual infrastructure, encrypting ESXi/Hyper‑V datastores, and leverages SMB (TCP 445) and RDP (TCP 3389) for lateral movement. Beyond encryption, the threat actor carries out double‑extortion by exfiltrating data through a Tor-based command‑and‑control channel before or while encrypting critical files. Victims are contacted through disposable email addresses and the encrypted Tox client qTox, where ransom notes (README.TXT, READ-ME.txt) advise on payment terms and delivery. Ransomware also steals credentials from browsers, Windows Credential Manager, VNC, Wi‑Fi profiles, and uses a malicious digitally signed driver to disable host endpoint protection. The actor’s operational pattern indicates a modular code base repurposed from earlier ransomware families (Beast/Monster) and a tendency toward rebranding. Community decryptors such as No More Ransom are currently ineffective due to the unique key‑management scheme, making data recovery dependent on clean backups or forensic data exfiltration analysis.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Healthcare
Financial services
Construction
Government
Critical infrastructure
Transportation
Manufacturing
Energy
Oil gas
Hospitality
Defense
Education
Telecommunications
Retail
Information technology

Targeted Countries / Regions

US
PK
CA
AU
BR
FR
IL
IR
RU

AI Analysis

Grounded in web research
· analyzed in 20 chunks · 5 days ago

Executive Summary

goddamn ransomwhere is a medium‑sophistication criminal ransomware-as-a-service actor that encrypts files with AES‑256-CBC combined with RSA‑2048 key wrapping, appending a .God8Damn extension and victim ID. The campaign employs double‑extortion tactics by exfiltrating data over Tor before or during encryption, and targets Windows, Linux, NAS, and virtualized environments (ESXi, Hyper‑V) through phishing attachments, SMB/RDP lateral movement, and remote services.

Goals & Targeting

The primary strategic objective of goddamn ransomwhere is financial gain through ransomware extortion and double‑extortion campaigns. By encrypting data and threatening to publish or sell exfiltrated information, the actor maximizes leverage over victims, especially those in high‑value sectors such as healthcare and critical infrastructure. The targeting profile favors enterprises with significant on‑prem, virtualized, or NAS deployments that rely heavily on consistent, unencrypted backups, thereby increasing the likelihood of payment.

Enhanced Description

Key Capabilities

  • Hybrid encryption using AES‑256‑CBC per file with RSA‑2048 key wrapping
  • Persistence via random Windows service in %ProgramData% and logon‑triggered scheduled task created with schtasks.exe
  • Virtualization targeting (ESXi, Hyper‑V) to encrypt VM datastores
  • Lateral movement through SMB (TCP 445) and RDP (TCP 3389) connections
  • Double extortion via data exfiltration using Tor-based C2 before or during encryption
  • Remote access persistence using AnyDesk
  • Credential theft from web browsers, Windows Credential Manager, VNC, Wi‑Fi profiles, and email clients
  • Malicious Microsoft‑signed driver to disable antivirus and endpoint protection
  • Victim communication through disposable email addresses and qTox/Tox messaging client
  • File manipulation: appending unique victim ID and .God8Damn extension, ransom note generation with README.TXT or generic filenames (READ-ME.txt)
  • Distribution via phishing emails with malicious attachments

MITRE ATT&CK Tactics

Impact
Persistence
Exfiltration
Defense Evasion
Initial Access
Credential Access
Execution

ATT&CK Techniques

T1543.003
T1053
T1021.004
T1486
T1133
T1003
T1562.001
T1566
T1193
T1204.002

Software / Tooling

GodDamn ransomware (.God8Damn extension)
AnyDesk remote control tool
qTox messaging client
Tor anonymity network (C2)
Malicious signed Windows driver

Campaigns & Victims

goddamn ransomwhere has documented activity through early 2024, with confirmed incidents against US healthcare organizations and other enterprises. The actor employs a ransomware‑as‑a‑service model that rebrands older code from the Beast/Monster lineage, delivering malware via phishing attachments or compromised sites. Campaigns typically involve double‑extortion, encrypting files on local and external storage while exfiltrating data before or during attack. Operations are conducted with medium frequency, targeting both on‑prem and virtualized systems; the persistent use of Tor nodes for command‑and‑control suggests a reliance on stealth and anonymity in communication.

IOC Patterns

  • Email addresses (e.g., god8damn@hotmail.com, god8damn@cyberfear.com)
  • File extension .God8Damn or generic extensions (.enc, .encrypted)
  • Victim ID prefix such as [1CAAA6F2-2B17B6E6] in file names
  • AES‑256-CBC key encryption per file RSA‑2048 key wrapping of symmetric keys
  • Windows service creation in %ProgramData% with random name
  • Scheduled task via schtasks.exe to trigger on logon
  • Tor network usage for C2 connections
  • qTox ID 'qtox:ABAA98879B...' used for communication
  • Malicious signed driver disabling antivirus and endpoint protection

Recommended Actions

  • Disable SMB (TCP 445) and RDP (TCP 3389) outbound traffic from untrusted endpoints
  • Isolate infected VLANs or subnets to contain lateral movement
  • Never reboot infected servers; preserve memory dumps and system state
  • Reset domain administrator and privileged service account passwords immediately Revoke exposed Kerberos tickets
  • Air‑gap backup repositories to ensure offline integrity—verify backups before restoring
  • Restore only from validated, verified, immutable copies of data
  • Run forensic audit scripts (e.g., PowerShell IOC scanners) to identify persistence artifacts
  • Use reputable AV tools such as Combo Cleaner or Microsoft Defender to remove active infections
  • Block outbound Tor traffic to prevent C2 communication
  • Monitor for abnormal cryptographic operations and suspicious file‑extension changes through EDR solutions
  • Implement regular user phishing awareness training Enforce multi-factor authentication on critical systems
  • Maintain redundant, geographically distributed backups—test restoration procedures periodically

Suggested Tags

ransomware
hybrid encryption
AES‑256‑CBC
RSA‑2048
double extortion
data exfiltration
cybercrime
financial gain
critical infrastructure
healthcare sector
virtualized environments
ESXi
Hyper‑V
SMB lateral movement
RDP lateral movement
email-based phishing
qTox communications
AnyDesk remote control
Tor C2
credential theft
malicious signed driver
scheduled task persistence
Windows service persistence

Confidence Assessment

The information is derived from multiple vendor reports, security blogs, and publicly available incident documentation, giving a moderate‑to‑high confidence level in the attacker’s technical capabilities and operational patterns. However, specific victim numbers, exact financial demands, and precise sector coverage are incomplete, leaving gaps in full attribution accuracy.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

Intel Summary

0

Techniques

45

Tools

0

Campaigns

24

IOCs

0

Observed Data

0

Tactics

Tags

ransomware
hybrid encryption
AES‑256‑CBC
RSA‑2048
double extortion
data exfiltration
cybercrime
financial gain
critical infrastructure
healthcare sector
virtualized environments
ESXi
Hyper‑V
SMB lateral movement
RDP lateral movement
email-based phishing
qTox communications
AnyDesk remote control
Tor C2
credential theft
malicious signed driver
scheduled task persistence
Windows service persistence

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
China (CN)
Confidence
80%
Added
Jul 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.