A Thanos ransomware campaign targeting mid-level employees at companies in Austria, Switzerland, and Germany has been met with victims refusing to pay the ransom demanded by hackers to decrypt their data.
Thanos ransomware is a Ransomware-as-a-Service (RaaS) feature advertised in Russian-speaking hacking circles that allows affiliates to customize their own ransomware via a builder offered by the developer.
Some samples of Thanos ransomware were previously flagged as a strain of ransomware called Hakbit – Insikt Group says it is the same malware.
“Based on code similarity, string reuse, and basic functionality, Insikt Group estimates that the ransomware samples referred to as Hakbit are constructed using the Thanos ransomware developed by Nosophoros,” Insikt Group said in early June.

GuLoader used Thanos payloads
The attacks began with a low-volume phishing campaign that spread malicious Microsoft Excel attachments sent from email accounts registered on the servers of free email provider GMX, says Proofpoint, which detected these attacks.
The phishing campaign focused on employees who serve customers with public business contact information, such as customer advisors, lawyers, insurance consultants, managers, and project managers.
“The targeted users were employed in mid-level positions in the pharmaceutical, legal, financial, business, retail , and healthcare sectors,” Proofpoint said.
“The largest volume of messages we observed were sent to the IT, construction, insurance and technology.”
The phishing emails delivered attachments that were invoices and tax return documents, which downloaded the GuLoader malware (also known as CloudEyE and vbdropper).
To ensure that malicious attachments are opened on a device that the ransomware payloads can encrypt, attackers instruct targets to download the attachments to their computers.
“Please note that for technical reasons the Excel does not display properly on mobile devices,” the emails state. “We ask that you download the invoice to computer and open it.”
Once the program is downloaded to victims' computers, it launches a Thanos ransomware payload accompanied by built-in file theft and automatic spread.
Recorded Future said earlier this month that the documents that Thanos ransomware steals by default are “.docx”, “.xlsx”, “.pdf” and “.csv”.
Thanos uses the PSExec program to download ransomware that can be executed on computers that will be encrypted using AES-256 encryption.
Victims refuse to surrender to Thanos ransomware demands
After encryption, the ransomware warned companies/victims in Europe that they had been hacked and informed them via a note that they must pay 250 euros worth of bitcoin.
Unfortunately for the operators of the Thanos ransomware, German, Austrian, and Swiss companies rejected their ransom demands
“As of June 16, 2020, our researchers have not found any transactions indicating the payment of the ransom in bitcoin” used as part of the campaign monitored by Proofpoint’s research team.
