logo

Ransomware Uses ChaCha20 and Curve25519 to Encrypt Windows Files

ID: 1fd6fc7f-d353-5f50-b10d-f5d471ef6c4c

STIX ID: report--1fd6fc7f-d353-5f50-b10d-f5d471ef6c4c

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Mayura Kathir

...
...

Payload is a newly public Windows ransomware family that uses per-file Curve25519 ECDH to derive ChaCha20 keys and appends RC4-encrypted footers, making encrypted data unrecoverable without the attackers' private key; it also includes aggressive anti-forensics (ETW patching, VSS deletion, event-log wiping) and process/service termination. First observed in Feb 2026 with a global double-extortion leak site and dozens of victims across multiple sectors (notably logistics and real estate), the group pressures victims via Tor-based negotiation sites and explicit timing threats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.