PE32 Ransomware: A New Telegram-Based Threat on the Rise
April 22, 2025, 10:17 p.m.
Description
PE32 Ransomware is a new strain of malware that utilizes Telegram for command and control. Despite its amateur execution, it effectively encrypts files and causes significant damage. The ransomware features a unique two-tiered payment model, demanding one fee to unlock files and another to prevent data leaks. It communicates entirely via Telegram Bot API, with the bot token exposed in the code. PE32 is characterized by its messy and loud behavior, dropping marker files, triggering disk repairs, and encrypting even useless files. While lacking sophisticated evasion techniques, it poses a real threat due to its fast encryption process and the current state of poor security hygiene among potential victims. The malware's reliance on basic Windows libraries and its chaotic codebase make it both easy to analyze and potentially dangerous.
Tags
Date
- Created: April 22, 2025, 3:57 p.m.
- Published: April 22, 2025, 3:57 p.m.
- Modified: April 22, 2025, 10:17 p.m.
Indicators
- 9e561018034479df1493addca30f1d031b9185e1d66f15333b8ea79d16acf64b
- c6ddc9c2852eddf30f945a50183e28d38f6b9b1bbad01aac52e9d9539482a433
- 15cb6bd05a35fdbd9a7e53b092a1b0537c64cb5df08ee0262479c0cc24eafd8a
- 5946bdeb8b7bf0603e99cefb15c083a37352fa8a916b2664bbb9f9027f44985b
- 098ee778fca1bfd809499dac65f528ea727f2aee9c6eaf79fe662d9261086e4a
Attack Patterns
- PE32 Ransomware