Archiveus is an early ransomware Trojan identified in 2006 that targets Microsoft Windows systems. It is notable as one of the first ransomware families reported to use 1,024-bit RSA encryption, marking an early step in the evolution from crude extortion malware to stronger cryptographic ransomware. Archiveus encrypts victim files, with reporting indicating a primary focus on data stored in the user's documents directory, and then withholds access in exchange for victim action intended to benefit the operators.
Unlike later ransomware families that typically demanded direct electronic payment, Archiveus used an extortion model in which victims were instructed to purchase goods from designated online stores in order to receive a decryption password. The malware required a long password to restore access to encrypted data. Its protection scheme was later broken, which significantly reduced its effectiveness.
Archiveus is consistently characterized as a Windows ransomware Trojan rather than a worm or self-propagating threat. It played an important historical role in ransomware development by demonstrating stronger asymmetric encryption in criminal extortion malware, even though it is no longer considered a prevalent threat.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware notable for early use of 1,024-bit RSA encryption, though weakened by reuse of passwords for unlocking systems.
Historical ransomware family referenced as an example of improved encryption schemes in early ransomware evolution.
2006 Agent.AWF Archiveus Clickbot Orbit Downloader Rustock Stration Zlob
Windows ransomware/Trojan used for extortion that encrypts user files, primarily in the My Documents directory, and demands that victims obtain a 30-digit password after purchasing something on specific websites to decrypt the files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.