Ransomware Group intelligence
Atomsilo
InactiveTrack Atomsilo with 8 published victims and 3 known leak locations in a single intelligence view.
Overview
Atomsilo is tracked by Breach House as a ransomware group with 8 published victims.
Brazil is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Up checked 3h ago | npmh5ahrgakbniuntyc7io4adm6ietbdbuejrfonowqtyqn24or556qd.onion |
| Leak location 1 | Onion service | Down checked 3h ago | mhdehvkomeabau7gsetnsrhkfign4jgnx3wajth5yb5h6kvzbd72wlqd.onion |
| Leak location 2 | Onion service | Down checked 3h ago | l5cjga2ksw6rxumu5l4xxn3cmahhi2irkbwg3amx6ajroyfmfgpfllid.onion |
Top Activity Sectors (5)
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue Atomsilo, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: atomsilo executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: atomsilo modifies registry run keys to ensure malware execution upon system reboot for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: atomsilo disables antivirus tools and modifies security software configurations to evade detection during ransomware deployment.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.016 Junk Code Insertion Stealth
What they do: atomsilo embeds junk code within its binaries to evade static analysis and detection by security tools.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: atomsilo deletes Volume Shadow Copies and backup directories via command-line utilities to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: atomsilo scans network shares using native tools to identify victim hosts for lateral movement and data targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1486 Data Encrypted for Impact Impact
What they do: atomsilo encrypts critical files and system resources using custom encryption routines to maximize impact and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: atomsilo invokes system recovery inhibition commands to block forensic analysis and persistence mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
atomsilo.hta
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Atom Slio: Instructions</title>
<HTA:APPLICATION APPLICATIONNAME="Atom Slio" SCROLL="yes" SINGLEINSTANCE="yes" WINDOWSTATE="maximize">
<style type="text/css">
.text{
text-align:center;
}
a {
color: #04a;
text-decoration: none;
}
a:hover {
text-decoration: underline;
}
body {
background-color: #e7e7e7;
color: #222;
font-family: "Lucida Sans Unicode", "Lucida Grande", sans-serif;
font-size: 13pt;
line-height: 19pt;
}
body, h1 {
margin: 0;
padding: 0;
}
hr {
color: #bda;
height: 2pt;
margin: 1.5%;
}
h1 {
color: #555;
font-size: 14pt;
}
ol {
padding-left: 2.5%;
}
ol li {
padding-bottom: 13pt;
}
small {
color: #555;
font-size: 11pt;
}
.button:hover {
text-decoration: underline;
}
.container {
background-color: #fff;
border: 2pt solid #c7c7c7;
margin: 5%;
min-width: 850px;
padding: 2.5%;
}
.header {
border-bottom: 2pt solid #c7c7c7;
margin-bottom: 2.5%;
padding-bottom: 2.5%;
}
.hr {
background: #bda;
display: block;
height: 2pt;
margin-top: 1.5%;
margin-bottom: 1.5%;
overflow: hidden;
width: 100%;
}
.info {
background-color: #f3f3fc;
border: 2pt solid #bda;
display: inline-block;
padding: 1%;
text-align: center;
box-sizing:border-box;
border-radius:20px;
}
.info1 {
background-color: #f3f3fc;
border: 2pt solid #bda;
display: inline-block;
padding: 1%;
text-align: center;
box-sizing:border-box;
border-radius:20px;
}
.h {
display: none;
}
.ml1{
position:absolute;width:50%;height:10rem;left:-211px;top:0;background:#f3f3fc;border:1px solid #cfd3da;box-sizing:border-box;padding:2% 2%
}
</style>
</head>
<body>
<div class="container">
<div class="header">
<h1>Atom Slio</h1>
<small id="title">Instructions</small>
</div>
<div class="text">
<span style="color:#f71b3a;font-size:40px">WARNING! YOUR FILES ARE ENCRYPTED AND LEAKED!</span>
</div>
<hr></hr>
<div class="info1">
<p>We are AtomSilo.Sorry to inform you that your files has been obtained and encrypted by us.</p>
<p>But don’t worry, your files are safe, provided that you are willing to pay the ransom.</p>
<p>Any forced shutdown or attempts to restore your files with the thrid-party software will be <span style="color:#f71b3a">damage your files permanently!</span></p>
<p>The only way to decrypt your files safely is to buy the special decryption software from us. </p>
<p>The price of decryption software is <span style="color:#f71b3a">1000000 dollars</span>. <br>If you pay within 48 hours, you only need to pay <span style="color:#f71b3a">500000 dollars</span>. No price reduction is accepted.</p>
<p>We only accept Bitcoin payment,you can buy it from bitpay,coinbase,binance or others. </p>
<p>You have five days to decide whether to pay or not. After a week, we will no longer provide decryption tools and publish your files</p>
</div>
<hr></hr>
<div align="center">
<span style="color:#f71b3a;font-size:200%">Time starts at 0:00 on September 11</span>
<hr></hr>
<span style="color:#f71b3a;font-size:300%">
<a>Survival time:</a>
<span id="td"></span>
<span id="th"></span>
<span id="tm"></span>
<span id="ts"></span>
</span>
</div>
<script type="text/javascript">
function getRTime(){
var EndTime= new Date('2021/09/16 00:00:00');
var NowTime = new Date();
var t =EndTime.getTime() - NowTime.getTime();
var d=Math.floor(t/1000/60/60/24);
var h=Math.floor(t/1000/60/60%24);
var m=Math.floor(t/1000/60%60);
var s=Math.floor(t/1000%60);
document.getElementById("td").innerHTML = d + " Day ";
document.getElementById("th").innerHTML = h + " Hour ";
document.getElementById("tm").innerHTML = m + " Min ";
document.getElementById("ts").innerHTML = s + " Sec ";
}
setInterval(getRTime,1000);
</script>
<hr></hr>
<p>You can contact us with the following email:
<p><a href="mailto:[email protected]"><span class="info">Email:[email protected]</span></a></p>
<p>If this email can't be contacted, you can find the latest email address on the following website:</p>
<p><span class="info"><a href="http://mhdehvkomeabau7gsetnsrhkfign4jgnx3wajth5yb5h6kvzbd72wlqd.onion" target="_blank">http://mhdehvkomeabau7gsetnsrhkfign4jgnx3wajth5yb5h6kvzbd72wlqd.onion</a></span></p>
<hr>
<p>If you don’t know how to open this dark web site, please follow the steps below to installation and use TorBrowser:</p>
<ol>
<li>run your Internet browser</li>
<li>enter or copy the address <a href="https://www.torproject.org/download/download-easy.html.en" target="_blank">https://www.torproject.org/download/download-easy.html.en</a> into the address bar of your browser and press ENTER</li>
<li>wait for the site loading</li>
<li>on the site you will be offered to download TorBrowser; download and run it, follow the installation instructions, wait until the installation is completed</li>
<li>run TorBrowser</li>
<li>connect with the button "Connect" (if you use the English version)</li>
<li>a normal Internet browser window will be opened after the initialization</li>
<li>type or copy the address in this browser address bar and press ENTER</li>
<li>the site should be loaded; if for some reason the site is not loading wait for a moment and try again.</li>
</ol>
<p>If you have any problems during installation or use of TorBrowser, please, visit <a href="https://www.youtube.com/results?search_query=Install+Tor+Browser+Windows" target="_blank">https://www.youtube.com</a> and type request in the search bar "Install TorBrowser Windows" and you will find a lot of training videos about TorBrowser installation and use.</p>
<hr>
<p><strong>Additional information:</strong></p>
<p>You will find the instructions ("README-FILE-#COMPUTER#-#TIME#.hta") for restoring your files in any folder with your encrypted files.</p>
<p>The instructions "README-FILE-#COMPUTER#-#TIME#.hta" in the folders with your encrypted files are not viruses! The instructions "README-FILE-#COMPUTER#-#TIME#.hta" will help you to decrypt your files.</p>
<p>Remember! The worst situation already happened and now the future of your files depends on your determination and speed of your actions.</p>
</div>
<span class="h"><asf>[snip]</asf><csf>3</csf><bsf>MSEDGEWIN10</bsf></span></body></html>
ATOMSILO-README.html
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Atom Slio: Instructions</title>
<HTA:APPLICATION APPLICATIONNAME="Atom Slio" SCROLL="yes" SINGLEINSTANCE="yes" WINDOWSTATE="maximize">
<style type="text/css">
.text{
text-align:center;
}
a {
color: #04a;
text-decoration: none;
}
a:hover {
text-decoration: underline;
}
body {
background-color: #e7e7e7;
color: #222;
font-family: "Lucida Sans Unicode", "Lucida Grande", sans-serif;
font-size: 13pt;
line-height: 19pt;
}
body, h1 {
margin: 0;
padding: 0;
}
hr {
color: #bda;
height: 2pt;
margin: 1.5%;
}
h1 {
color: #555;
font-size: 14pt;
}
ol {
padding-left: 2.5%;
}
ol li {
padding-bottom: 13pt;
}
small {
color: #555;
font-size: 11pt;
}
.button:hover {
text-decoration: underline;
}
.container {
background-color: #fff;
border: 2pt solid #c7c7c7;
margin: 5%;
min-width: 850px;
padding: 2.5%;
}
.header {
border-bottom: 2pt solid #c7c7c7;
margin-bottom: 2.5%;
padding-bottom: 2.5%;
}
.hr {
background: #bda;
display: block;
height: 2pt;
margin-top: 1.5%;
margin-bottom: 1.5%;
overflow: hidden;
width: 100%;
}
.info {
background-color: #f3f3fc;
border: 2pt solid #bda;
display: inline-block;
padding: 1%;
text-align: center;
box-sizing:border-box;
border-radius:20px;
}
.info1 {
background-color: #f3f3fc;
border: 2pt solid #bda;
display: inline-block;
padding: 1%;
text-align: center;
box-sizing:border-box;
border-radius:20px;
}
.h {
display: none;
}
.ml1{
position:absolute;width:50%;height:10rem;left:-211px;top:0;background:#f3f3fc;border:1px solid #cfd3da;box-sizing:border-box;padding:2% 2%
}
</style>
</head>
<body>
<div class="container">
<div class="header">
<h1>Atom Silo</h1>
<small id="title">Instructions</small>
</div>
<div class="text">
<span style="color:#f71b3a;font-size:40px">WARNING! YOUR FILES HAVE BEEN STOLEN AND WILL BE LEAKED!</span>
<hr></hr>
<div class="info1">
<p>We are AtomSilo. We regret to inform you that your files have been <strong>accessed and stolen</strong> by us.</p>
<p>But don't worry, your files are safe, provided that you are willing to pay the ransom. </p>
<p>Any attempt to involve third parties or perform forensic analysis will result in <span style="color:#f71b3a">the immediate release of your stolen data.</span></p>
<p>The only way to prevent publication is to purchase our data-deletion guarantee.</p>
<p>The price for deleting your stolen data is <span style="color:#f71b3a">50 BTC</span>. <br>If you pay within 24 hours, the price is reduced to <span style="color:#f71b3a">25 BTC</span>. No further negotiation will be accepted.</p>
<p>We only accept Bitcoin payments. You can buy BTC using BitPay, Coinbase, Binance, or others.</p>
<p>You have five days to decide whether to pay. After seven days, we will no longer negotiate and will publish all stolen data.</p>
</div>
</div>
<hr></hr>
<div align="center">
<span style="color:#f71b3a;font-size:200%">Time starts at 22:00 on February 22</span>
<hr></hr>
<span style="color:#f71b3a;font-size:300%">
<a>Survival time:</a>
<span id="td"></span>
<span id="th"></span>
<span id="tm"></span>
<span id="ts"></span>
</span>
</div>
<script type="text/javascript">
function getRTime(){
var EndTime = new Date('2026-02-27T22:00:00+08:00');
var NowTime = new Date();
var t =EndTime.getTime() - NowTime.getTime();
var d=Math.floor(t/1000/60/60/24);
var h=Math.floor(t/1000/60/60%24);
var m=Math.floor(t/1000/60%60);
var s=Math.floor(t/1000%60);
document.getElementById("td").innerHTML = d + " Day ";
document.getElementById("th").innerHTML = h + " Hour ";
document.getElementById("tm").innerHTML = m + " Min ";
document.getElementById("ts").innerHTML = s + " Sec ";
}
setInterval(getRTime,1000);
</script>
<hr></hr>
<p>You can contact us with the following TOX ID:
<p><a href="https://tox.chat/download.html"><span class="info">TOX ID:F3675A6D571BEAE0CA3F0C1E88A219915EC7E9D6B84F67A0A16989B4A17A7F1DD509997D91D3</span></a></p>
<p>If this TOX ID can't be contacted, you can find the latest TOX ID on the following website:</p>
<p><span class="info"><a href="http://npmh5ahrgakbniuntyc7io4adm6ietbdbuejrfonowqtyqn24or556qd.onion" target="_blank">http://npmh5ahrgakbniuntyc7io4adm6ietbdbuejrfonowqtyqn24or556qd.onion</a></span></p>
<hr>
<p>If you don’t know how to open this dark web site, please follow the steps below to installation and use TorBrowser:</p>
<ol>
<li>run your Internet browser</li>
<li>enter or copy the address <a href="https://www.torproject.org/download/download-easy.html.en" target="_blank">https://www.torproject.org/download/download-easy.html.en</a> into the address bar of your browser and press ENTER</li>
<li>wait for the site loading</li>
<li>on the site you will be offered to download TorBrowser; download and run it, follow the installation instructions, wait until the installation is completed</li>
<li>run TorBrowser</li>
<li>connect with the button "Connect" (if you use the English version)</li>
<li>a normal Internet browser window will be opened after the initialization</li>
<li>type or copy the address in this browser address bar and press ENTER</li>
<li>the site should be loaded; if for some reason the site is not loading wait for a moment and try again.</li>
</ol>
<p>If you have any problems during installation or use of TorBrowser, please, visit <a href="https://www.youtube.com/results?search_query=Install+Tor+Browser+Windows" target="_blank">https://www.youtube.com</a> and type request in the search bar "Install TorBrowser Windows" and you will find a lot of training videos about TorBrowser installation and use.</p>
<hr>
<p><strong>Additional information:</strong></p>
<p>You will find the instructions for retrieving your files on the TOX chat after contacting us.</p>
<p>Remember! The worst situation already happened and now the future of your files depends on your determination and speed of your actions.</p>
</div>
<span class="h"><asf>[snip]</asf><csf>3</csf><bsf>MSEDGEWIN10</bsf></span></body></html>
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (8)
Search, filter and paginate the victim timeline for Atomsilo. Showing 1–8 of 8.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | A large bank in Asia id26816 View details | Finance / Legal / Insurance | |||
|
[AI generated] A large bank in Asia refers to a financial institution that provides diversified services like deposits, loans, wealth management to individual and corporate clients. Being large-scale, they generally operate across several countries in the Asia region, often having a significant market share. This also involves operating digital banking services, given the widespread internet usage. Their influence in the finance sector can affect regional economic stability. |
|||||
| Ransomware | Tegravendas id2266 View details | Other | — | ||
|
Tegravendas is a business entity operating within the services sector, primarily associated with commercial activities in Brazil. The organization provides various professional or operational services to its client base. This entity has been identified and listed as a ransomware victim associated with the threat actor group known as atomsilo. |
|||||
| Ransomware | Tegra Vendas id26815 View details | Brazil | Agriculture / Food | ||
|
[AI generated] N/A |
|||||
| Ransomware | Eisai Co., Ltd. id2265 View details | Services | — | ||
|
Eisai Co., Ltd. is a prominent Japanese pharmaceutical company headquartered in Tokyo that operates within the global healthcare services sector. The organization focuses on the research, development, and marketing of prescription medicines across various therapeutic areas, including neurology and oncology. As a research-driven entity, Eisai maintains a significant international presence to support its pharmaceutical product pipeline and patient care initiatives. This entity has been identified as a ransomware victim in a listing associated with the threat actor group known as AtomSilo. |
|||||
| Ransomware | Eisai Co., Ltd id26814 View details | Japan | Healthcare / Pharma | ||
|
[AI generated] Eisai Co., Ltd. is a Japanese multinational pharmaceutical company headquartered in Tokyo. Established in 1941, it's one of the leading firms in the field of neurology and oncology. Eisai produces several drugs used globally such as Aricept for Alzheimer's disease and Halaven for breast cancer. Aside from drug creation, Eisai also engages in global health initiatives. |
|||||
| Ransomware | LIGHT CONVERSION id2264 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Cristália - Indústria Farmacêutica id2263 View details | Agriculture / Food | — | ||
|
Cristália Indústria Farmacêutica is a prominent Brazilian pharmaceutical company headquartered in Itapira, São Paulo, specializing in the research, development, and manufacturing of innovative medicines, active pharmaceutical ingredients, and hospital supplies. While the organization maintains a primary focus on the pharmaceutical and healthcare sectors, it also operates significant agricultural and food-related divisions involved in the production of raw materials and specialized inputs. The company maintains a robust presence across the Latin American market, providing critical medical solutions and industrial products. This entity has been listed as a ransomware victim associated with the threat actor group known as AtomSilo. |
|||||
| Ransomware | Cristália - Indústria Farmacêutica id26813 View details | Brazil | Healthcare / Pharma | ||
|
[AI generated] Cristália - Indústria Farmacêutica is a premier pharmaceutical company based in Brazil. Founded in 1972, it is renowned for contributing to major advancements in the medical and pharmaceutical field. The company produces medicines, hospital products, and active pharmaceutical ingredients. Cristália stands out in the industry with over 200 patents and specializes in various therapeutic classes, including psychiatry, anesthesia, and oncology. |
|||||