logo

AtomSilo Ransomware Enters the League of Double Extortion

ID: 58ad5b6f-a692-56e7-a414-69e61e03ac68

STIX ID: report--58ad5b6f-a692-56e7-a414-69e61e03ac68

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

AtomSilo is a double-extortion ransomware group active since ~September 2021; this report provides a technical analysis of their intrusion vector (Confluence exploit and DLL side-loading), post-exploitation techniques (WMI execution, use of admin accounts), encryption mechanics (XOR + AES with AESKEYGENASSIST, chunked encryption, .atomsilo file extension), exclusions/ransom note behavior, and leak-site operations including a published ~900 GB dataset and at least one MD5 IOC.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.