TaRRaK is a .NET-based ransomware variant first detected in mid-2021. It is notable for multiple coding and encryption flaws, and Avast researchers developed a free decryptor that allows victims to recover files without negotiating with the operators. The malware does not use obfuscation or other code-evasion protections. It creates a mutex named "TaRRaK" to ensure only one instance runs and establishes persistence via a registry autorun entry executed at each logon. TaRRaK targets files matching a list of 178 file extensions, avoids certain system paths including "$Recycle.Bin", ":\Windows", "\Program Files", "\Local\Microsoft", and ":\ProgramData", and appends the ".TaRRaK" extension to encrypted files. Its encryption implementation is highly flawed: it reads entire files into memory using File.ReadAllBytes(), which imposes a 2 GB limit; it mishandles exceptions; on permission-denied errors it adds an ACL granting full access to everyone and retries; and on other errors it can rethrow exceptions and enter an infinite loop. During encryption it converts file bytes into 32-bit integers, uses a custom encryption algorithm, and allocates additional memory blocks equal to the file size, which can also trigger failures and looping if memory allocation fails. When encryption succeeds, TaRRaK drops a ransom note in the root folder of compromised drives and displays a message on the victim desktop. Known high-confidence indicators and artifacts mentioned in the content include the mutex name "TaRRaK" and the ".TaRRaK" file extension.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET ransomware family that encrypts files, appends the .TaRRaK extension, creates a mutex and auto-start registry entry for persistence, drops a ransom note, and displays a desktop message. Its encryption implementation is flawed, with multiple coding and memory-handling bugs that enabled development of a free decryptor.
Ransomware escrito en .NET que cifra archivos, añade la extensión .TaRRaK, crea un mutex llamado TaRRaK, establece persistencia mediante una clave de autoarranque en el registro y deja una nota de rescate. Su implementación contiene múltiples errores de programación que permitieron desarrollar una herramienta de descifrado gratuita.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.