Hidden Tear

Hidden Tear is the first open-source ransomware trojan that targets computers running Microsoft Windows[1] The original sample was posted in August 2015 to GitHub.[2]

Hidden Tear
Technical nameRansom.MSIL.Tear
ClassificationTrojan horse
TypeRansomware
SubtypeCryptovirus
Point of originIstanbul, Turkey
Author(s)Utku Sen
Operating system(s) affectedMicrosoft Windows
Written inC#

When Hidden Tear is activated, it encrypts certain types of files using a symmetric AES algorithm, then sends the symmetric key to the malware's control servers.[3] However, as Utku Sen claimed "All my malware codes are backdoored on purpose", Hidden Tear has an encryption backdoor, thus allowing him to crack various samples.[4]

References

This article is issued from Wikipedia. The text is licensed under Creative Commons - Attribution - Sharealike. Additional terms may apply for the media files.