Hidden Tear is an open-source ransomware family published to GitHub by Turkish security researcher Utku Sen and presented as an educational project. It is a functional ransomware implementation that uses AES encryption to lock victim files, can drop a text ransom note on the desktop, and can display a scare warning or ransom message to pressure victims into paying. Reported target file types include common office documents such as word processor files, spreadsheets, and PowerPoint files. Contemporary reporting characterized it as less sophisticated than major ransomware families such as CryptoWall and CryptoLocker, and noted that implementation errors made some Hidden Tear-based infections easier to decrypt and detect.
Although created for educational purposes, Hidden Tear has been abused by threat actors in real operations. The content specifically notes its execution by RATVERMIN operators during activity targeting the Ukrainian government; in that case the ransomware was saved as hell0.exe with MD5 8ff9bf73e23ce2c31e65874b34c54eac, though the process was killed before successful execution. The content also states that a probable CARBON SPIDER actor deployed the open-source Hidden Tear ransomware in June 2021 during a ransomware operation, assessed as occurring after the Colonial Pipeline incident. In addition, a joint NSA/FBI/CISA/HHS/NIS/DSA advisory states DPRK state-sponsored actors have been observed using or possessing publicly available encryption tools including Hidden Tear while targeting healthcare and other critical infrastructure organizations.
High-confidence indicators directly mentioned in the content include the sample name hell0.exe and MD5 hash 8ff9bf73e23ce2c31e65874b34c54eac associated with a Hidden Tear execution attempt. The malware is widely recognized as one of the first open-source ransomware projects, alongside EDA2, and its public availability lowered the barrier to entry for less sophisticated ransomware operators.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On April 29, CVE-2026-41940 was disclosed: a critical pre-authentication bypass in cPanel/WHM that lets remote attackers skip the login flow entirely and gain elevated access. Within 24 hours, it was already being weaponized.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An early ransomware tool cited as easy to detect and flawed in implementation, resulting in lower impact and easier decryption; it primarily targeted regular consumers rather than large organizations.
Open-source ransomware used by a probable CARBON SPIDER actor post-Colonial Pipeline, likely to reduce attention; associated with Demux, Sekur RAT, and Cobalt Strike usage for access/persistence.
Open-source ransomware project originally created for educational purposes; referenced as related to EDA2 and abused by threat actors to build/derive ransomware strains.
Openly published ransomware source code described as functional malware that uses AES encryption to lock files and displays a ransom or scare message; presented by its author as for educational purposes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.