Thanos ransomware, a C#/.NET-based RaaS platform whose builder source code leaked, spawned at least four double-extortion variants in 2021: Prometheus, Haron, Spook, and Midas. All variants share common signatures including the 'GotAllDone' file marker appended to encrypted files and key identifiers in ransom notes. The latest variant, Midas, terminates security and backup services, deletes shadow copies, disables the Raccine anti-ransomware tool, encrypts files using Salsa20 with RSA-wrapped keys, and maintains persistence via a startup LNK file.
Thanos Ransomware
1 post
A Study of Thanos Ransomware Variants | Zscaler Blog