atomsilo
ACTIVERansomware-as-a-Serviceransomware group
AtomSilo emerged in September 2021 and ceased operations by year-end 2021. It functioned with a double‑extortion model, combining file encryption with data exfiltration and leak threats. The malware uses a hybrid encryption scheme—AES‑256 for file encryption and RSA‑4096 to secure the AES key—and appends the extension .ATOMSILO to encrypted files. Ransom notes follow formats like README-FILE-{computer name}-{timestamp}.hta or ATOMSILO-README.hta. Structurally and operationally, AtomSilo closely resembles the LockFile ransomware and is attributed to the Chinese state-linked actor BRONZE STARLIGHT (aka Cinnamon Tempest, DEV‑0401, Emperor Dragonfly, SLIME34), likely serving as a smokescreen for espionage-driven data theft. Victims spanned multiple industries and countries, including notable high extortion demands up to $1 million USD. The group also exploited the Atlassian Confluence vulnerability (CVE‑2021‑26084) for initial access and used DLL side‑loading for stealthy deployment.
Group Activity
Last 12 monthsVictims (10)
Updates of data storage rules
Dear companies, now we store your data on our tor servers.
New contacts
Please contact us through the email provided by us.
A large bank in Asia
[AI generated] A large bank in Asia refers to a financial institution that provides diversified services like deposits, loans, wealth management to individual a...
Tegravendas
Tegra Vendas
[AI generated] N/A
Eisai Co., Ltd.
Eisai Co., Ltd
[AI generated] Eisai Co., Ltd. is a Japanese multinational pharmaceutical company headquartered in Tokyo. Established in 1941, it's one of the leading firms in ...
LIGHT CONVERSION
Cristália - Indústria Farmacêutica
Cristália - Indústria Farmacêutica
[AI generated] Cristália - Indústria Farmacêutica is a premier pharmaceutical company based in Brazil. Founded in 1972, it is renowned for contributing to major...
Infrastructure
http://npmh5ahrgakbniuntyc7io4adm6ietbdbuejrfonowqtyqn24or556qd.onion1830ms
3d ago
http://npmh5ahrgakbniuntyc7io4adm6ietbdbuejrfonowqtyqn24or556qd.onion/leaks.html511ms
6d ago