TellYouThePass — Ransomware Profile
TellYouThePass is a financially motivated ransomware family that CrowdStrike traces back to early 2019 and that has been rewritten repeatedly, moving from Java and .NET builds to a Go version that surfaced in mid-December 2021 and encrypts both Windows and Linux hosts; in that build the authors left only one main function and renamed the others at random to make analysis harder, and the ransom note claims RSA-1024 and AES-256 encryption. Its defining habit is speed against freshly published n-day exploits rather than affiliate recruitment or a leak site: it adopted the Log4j exploit in December 2021 and an Apache ActiveMQ RCE in November 2023. Arctic Wolf Labs tied that ActiveMQ activity (CVE-2023-46604), observed in the wild from 10 October 2023, to the family through binary similarity plus reused IP addresses, domains and a Bitcoin wallet address. In June 2024 the operators moved on CVE-2024-4577, the PHP-CGI argument-injection flaw, with attacks starting 8 June — under 48 hours after PHP shipped fixes — using publicly available exploit code. Imperva reverse-engineered that chain, in which PHP code execution invoked mshta.exe to run a remote HTA carrying base64-encoded VBScript that loaded a .NET build of the encryptor into memory, then dropped a READ_ME10.html ransom note in the web root. Censys counted roughly 1,000 publicly exposed infected hosts as of 13 June 2024, primarily geolocated in China.
Vendor research
Read the full analysis on IntelFusions