Trojan.Encoder.35534 is an encoder trojan/ransomware family tracked by Dr.Web. Across Dr.Web’s quarterly reporting for Q4 2025 through Q2 2026, it was repeatedly identified as one of the most common ransomware families affecting users’ files and generating decryption requests. Dr.Web reported it as the leading family in user decryption requests in Q1 2026 at 15.59%, and as accounting for 24.90% of decryption requests in Q4 2025. In Q2 2026, it remained among the encoder trojans most commonly affecting users’ files, alongside families such as Trojan.Encoder.41868, Trojan.Encoder.37400, and Trojan.Encoder.29750. The provided content does not describe specific infection vectors, technical behavior beyond file encoding, targeted industries, associated threat actors, platforms, or indicators of compromise for this family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A file-encrypting encoder trojan/ransomware variant that was among the most common causes of decryption requests in Q2 2026.
File-encrypting trojan (encoder) affecting users in Q1 2026; one of the most common ransomware detections in Dr.Web telemetry.
Ransomware that encrypts files and demands payment for decryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.