EKANS Ransomware Misconceptions and Misunderstandings
ID: 50e0b370-5c06-51d0-ad61-b747d6ed3b61
STIX ID: report--50e0b370-5c06-51d0-ad61-b747d6ed3b61
Feed Name: Dragos Blog
Dragos analyzes the EKANS (aka SNAKE) ransomware first reported in January 2020, describing its embedded process-kill functionality targeting ICS-related processes (data historians, licensing servers) to remove file locks prior to encryption. The report clarifies misattribution to the Turla/SNAKE state actor, assesses EKANS as likely criminal monetization rather than state-directed sabotage, and warns that although functionality is blunt and unsophisticated compared with ICS-focused sabotage malware, EKANS poses a serious operational risk to industrial environments and warrants increased visibility and incident response capability.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
