Ransomware Uses ChaCha20 and Curve25519 to Encrypt Windows Files
ID: 1fd6fc7f-d353-5f50-b10d-f5d471ef6c4c
STIX ID: report--1fd6fc7f-d353-5f50-b10d-f5d471ef6c4c
Feed Name: GBHackers
Payload is a newly public Windows ransomware family that uses per-file Curve25519 ECDH to derive ChaCha20 keys and appends RC4-encrypted footers, making encrypted data unrecoverable without the attackers' private key; it also includes aggressive anti-forensics (ETW patching, VSS deletion, event-log wiping) and process/service termination. First observed in Feb 2026 with a global double-extortion leak site and dozens of victims across multiple sectors (notably logistics and real estate), the group pressures victims via Tor-based negotiation sites and explicit timing threats.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
