logo

Nokoyawa Ransomware: Rust or Bust

ID: 3cf9eded-9e7c-54ac-902f-938623afb7d4

STIX ID: report--3cf9eded-9e7c-54ac-902f-938623afb7d4

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-12-30

Date Updated: 2026-05-01

...
...

Nokoyawa 2.0 is a 64-bit Windows ransomware family rewritten in Rust that uses Curve25519 (x25519) for asymmetric key agreement and Salsa20 for symmetric encryption; it accepts a Base64-encoded JSON configuration via the command line, performs partial-file encryption for speed, and supports double-extortion via a TOR-hosted leak site — the report includes technical analysis, decryption tooling guidance (if private key available), and multiple SHA256 IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.