Ransomware Research
Saturn Ransomware
Saturn is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on February 1, 2018, this ransomware has been actively targeting systems worldwide. Security researchers also track this malware under the aliases: Saturn RaaS.
Quick Facts
- Ransomware Family
- Saturn
- First Seen
- February 1, 2018
- Known Aliases
- Saturn RaaS
How Saturn Ransomware Works
Targeted Files
https://app.any.run/tasks/b38b2d1f-c03f-419b-add8-42a45717e5e2/
File Encryption Patterns
Saturn modifies encrypted files using specific patterns to mark them as encrypted:
File extensions added after encryption:
..saturn
Ransom Note and Payment Demands
After encrypting files, Saturn displays ransom notes demanding payment for file recovery:
#DECRYPT_MY_FILES#.txt
Ransom message:
notes/#DECRYPT_MY_FILES#.txt
Note locations:
EveryFolder
#DECRYPT_MY_FILES#.html
Ransom message:
notes/#DECRYPT_MY_FILES#.html
Note locations:
EveryFolder
Ransom message:
notes/#DECRYPT_MY_FILES#.html
Note locations:
Desktop
#DECRYPT_MY_FILES#.vbs
Ransom message:
notes/#DECRYPT_MY_FILES#.vbs
Note locations:
Desktop
Technical Indicators
Associated Executable Files
The following executable files are associated with Saturn ransomware:
SATURN_RANSOM.exe
SATURN_RANSOM.bin
myfile.exe
Saturn.exe
stub
9e87f069de22ceac029a4ac56e630.exe
9e87f069de22ceac029a4ac56e630 (Saturn).exe
stub.exe
b3040fe60ac4408.exe
b3040fe60ac4408 (Saturn).exe
Elastio Can Help You
Don't let Saturn ransomware take over your data
Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.
About This Analysis
This Saturn ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like Saturn.
Last updated: July 30, 2025