Also known as: tracked as, Bjorka, SkyWave, quic, Colddraw Ransomware, built a, OffSec, Lolkek, medium-sized, medium-sized bu, targeting nume, Dispossessor, active since August 2023, RA World, Raznatovic, Linux VMware, 54BB47h, Fonix, Abyss Locker, ARCrypter, GlobeImposter, CosmicBeetle, PlayCrypt, N13V, operated by UNC2190, FonixCrypter
goddamn ransomwhere represents a modern ransomware-as-a-service operation that blends traditional cryptographic techniques with contemporary operational tactics. The malware encrypts each file individually using AES‑256‑CBC in conjunction with an RSA‑2048 key wrapped within the TLS‑style PKCS#1 v1.5 envelope, ensuring that decryption is only possible through the attacker’s key‑management infrastructure. Deployment typically occurs via spearphishing emails carrying malicious attachments or direct downloads from compromised sites; once executed, it establishes persistence by creating a Windows Service with a randomly generated name in %ProgramData% and spawns a scheduled task to run on user logon via schtasks.exe. The actor additionally targets virtual infrastructure, encrypting ESXi/Hyper‑V datastores, and leverages SMB (TCP 445) and RDP (TCP 3389) for lateral movement. Beyond encryption, the threat actor carries out double‑extortion by exfiltrating data through a Tor-based command‑and‑control channel before or while encrypting critical files. Victims are contacted through disposable email addresses and the encrypted Tox client qTox, where ransom notes (README.TXT, READ-ME.txt) advise on payment terms and delivery. Ransomware also steals credentials from browsers, Windows Credential Manager, VNC, Wi‑Fi profiles, and uses a malicious digitally signed driver to disable host endpoint protection. The actor’s operational pattern indicates a modular code base repurposed from earlier ransomware families (Beast/Monster) and a tendency toward rebranding. Community decryptors such as No More Ransom are currently ineffective due to the unique key‑management scheme, making data recovery dependent on clean backups or forensic data exfiltration analysis.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
goddamn ransomwhere is a medium‑sophistication criminal ransomware-as-a-service actor that encrypts files with AES‑256-CBC combined with RSA‑2048 key wrapping, appending a .God8Damn extension and victim ID. The campaign employs double‑extortion tactics by exfiltrating data over Tor before or during encryption, and targets Windows, Linux, NAS, and virtualized environments (ESXi, Hyper‑V) through phishing attachments, SMB/RDP lateral movement, and remote services.
Goals & Targeting
The primary strategic objective of goddamn ransomwhere is financial gain through ransomware extortion and double‑extortion campaigns. By encrypting data and threatening to publish or sell exfiltrated information, the actor maximizes leverage over victims, especially those in high‑value sectors such as healthcare and critical infrastructure. The targeting profile favors enterprises with significant on‑prem, virtualized, or NAS deployments that rely heavily on consistent, unencrypted backups, thereby increasing the likelihood of payment.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
goddamn ransomwhere has documented activity through early 2024, with confirmed incidents against US healthcare organizations and other enterprises. The actor employs a ransomware‑as‑a‑service model that rebrands older code from the Beast/Monster lineage, delivering malware via phishing attachments or compromised sites. Campaigns typically involve double‑extortion, encrypting files on local and external storage while exfiltrating data before or during attack. Operations are conducted with medium frequency, targeting both on‑prem and virtualized systems; the persistent use of Tor nodes for command‑and‑control suggests a reliance on stealth and anonymity in communication.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information is derived from multiple vendor reports, security blogs, and publicly available incident documentation, giving a moderate‑to‑high confidence level in the attacker’s technical capabilities and operational patterns. However, specific victim numbers, exact financial demands, and precise sector coverage are incomplete, leaving gaps in full attribution accuracy.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
45
Tools
0
Campaigns
24
IOCs
0
Observed Data
0
Tactics