RansomBoggs
RansomBoggs (canonical ESET naming per November 25, 2022 disclosure.
ESET detection signatures MSIL/Filecoder.Sullivan.A + MSIL/Filecoder.RansomBoggs.A; signature Monsters Inc. themed ransom note with James P. Sullivan persona) is a .NET (MSIL) ransomware-as-wiper deployed November 21, 2022 by Sandworm against multiple Ukrainian organizations (at least 5 per ESET spokeswoman Yulia Andrienko via The Record)
Russian state-sponsored APT attribution to Sandworm (Russian GRU Unit 74455, also Mandiant APT44 / Microsoft Seashell Blizzard / Microsoft IRIDIUM pre-weather / Dragos ELECTRUM, curated separately as sandworm_team parent operator) via ESET canonical POWERGAP PowerShell deployment- similarity attribution (per ESET: "There are similarities with previous attacks conducted by Sandworm: a PowerShell script used to distribute the .NET ransomware from the domain controller is almost identical to the one seen last April during the Industroyer2 attacks against the energy sector") + ESET APT Activity Report T3 2022 establishing Prestige + RansomBoggs as paired Sandworm ransomware-as-wiper operations late 2022.
standalone malware platform cluster paralleling prestige_ransomware + swiftslicer in 2023+ Sandworm destructive cyberweapon evolution cell.
operational attack architecture comprising POWERGAP PowerShell script deployment from AD domain controller (CERT-UA- named, cluster-defining cluster-cell coherence with v0.1.124 industroyer.yaml + v0.1.130 caddywiper.yaml, "almost identical" PowerShell script across April 2022 Industroyer2 + March 2022 CaddyWiper via ArguePatch loader + November 2022 RansomBoggs distribution) + cluster-defining AES-256 CBC encryption with random per-victim key (NOT AES-128 as ransom note misleadingly claims per ESET) + cluster-defining .chsch file extension on encrypted files + RSA-encrypted aes.bin key storage + variant flexibility with RSA public key hardcoded OR provided as argument per ESET analysis.
cluster- defining Monsters Inc. themed ransom note operator- trolling tradecraft (SullivanDecryptsYourFiles.txt filename + "Dear human life form!" salutation + "James P. Sullivan, an employee of Monsters, Inc." author persona referencing 2001 Pixar Monsters Inc. protagonist + Sullivan executable name + Monsters Inc. references throughout malware code + Telegram account named Sullivan + note text "We are relying on you in these hard times and are crying for help" per The Record)
signature destructive-operation- disguised-as-ransomware tradecraft echoing NotPetya 2017 + Prestige October 2022 lineage, per ESET APT Activity Report T3 2022: "Sandworm attacks using ransomware as a wiper... the final objective was the same as for the wipers: data destruction. Unlike traditional ransomware attacks, the Sandworm operators do not intend to provide a decryption key"; exclusively Ukraine-targeting per ESET telemetry (distinct from Prestige Ukraine + Poland targeting , operationally separate target scope)
.NET (MSIL) ransomware family distinct codebase from Prestige (C++) + SwiftSlicer (Go) demonstrating Sandworm multi-language destructive capability.
ESET January 27, 2023 SwiftSlicer disclosure retrospectively consolidated RansomBoggs + SwiftSlicer cluster-cell coherence ("Two months ago, ESET detected a wave of RansomBoggs ransomware attacks in the war-torn country that were also linked to Sandworm")
ESET DynoWiper January 30, 2026 retrospective catalogs RansomBoggs in chronological Sandworm destructive malware family (HermeticWiper + HermeticRansom + CaddyWiper + DoubleZero + ARGUEPATCH + ORCSHRED + SOLOSHRED + AWFULSHRED + Prestige ransomware + RansomBoggs ransomware + SDelete-based wipers + BidSwipe + ROARBAT + SwiftSlicer + NikoWiper + SharpNikoWiper + ZEROLOT + Sting wiper + ZOV wiper); cluster fills .NET ransomware-as-wiper position in 2023+ Sandworm destructive cyberweapon evolution cell.
canonical illustration of Monsters Inc.-themed operator-trolling ransom note tradecraft + POWERGAP PowerShell deployment continuity with Industroyer2 + CaddyWiper + Sandworm multi-language destructive capability development cited in essentially all subsequent Sandworm + Ukraine war + ransomware-as- wiper + .NET ransomware industry analyses through 2022-2026 period.