EKANS Ransomware and ICS Operations
ID: 32dada42-e3d9-5109-b1ca-d0e8cd6b20ba
STIX ID: report--32dada42-e3d9-5109-b1ca-d0e8cd6b20ba
Feed Name: Dragos Blog
Dragos analyzes EKANS, a Go-written ransomware first seen in late December 2019 that uniquely contains a hard-coded process kill list targeting many ICS and historian-related processes (e.g., Proficy components, HMIWeb, licensing servers). EKANS uses WMI to perform encryption, deletes Volume Shadow Copies, appends randomized characters to file extensions, drops a ransom note, and lacks any self-propagation—indicating it is intended to be deployed across environments via administrative access rather than worming. The report links EKANS to MEGACORTEX variants based on overlapping kill lists, provides sample hashes and a full targeted-process appendix, assesses potential operational impacts (loss of view, disruption) while noting limited sophistication, and gives defense and recovery recommendations for ICS asset owners.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
