Chily is a ransomware threat actor or campaign name associated with a custom-branded Windows locker built from the same codebase used by Vice Society and SunnyDay. Analysis of the payloads indicates the Chily-branded ransomware shares an identical executable codebase with a Vice Society-branded variant, with differences confined primarily to campaign-specific configuration such as ransom note content, file extension, wallpaper text, and embedded keying material. This strongly suggests Chily used ransomware supplied by a shared external developer or developer group rather than being merely another alias for Vice Society. The underlying locker family uses a hybrid cryptographic design combining NTRUEncrypt for asymmetric protection of key material and ChaCha20-Poly1305 for per-file encryption. It supports multithreaded encryption for speed and can recursively encrypt files across local drives, remote drives, and network shares. The broader code lineage and builder-like design indicate a specialized ransomware development service capable of producing custom-branded payloads and corresponding decryptors for multiple customers. Available reporting does not support attributing Chily to a specific country or linking it to a distinct nation-state sponsor. The observed activity is consistent with financially motivated ransomware operations. High-confidence public details about Chily’s victimology, geographic targeting, and operational history remain limited beyond its use of this shared ransomware codebase.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A separate threat group identified through use of a custom-branded ransomware payload built from the same codebase as Vice Society's PolyVice payload.
Mentioned only as a similar related variant derived from the Vice Society branch.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.