The Paradise ransomware operation, a long-running ransomware-as-a-service family first seen in 2017, drew renewed concern after the source code for its .NET variant was leaked on the Russian-speaking XSS forum. Researchers said the leak included the Paradise builder and a decryption utility, and analysts verified the files as authentic. Although the .NET branch had seen more limited use than the native Paradise version, newly built samples were reportedly being classified as undecryptable, raising the risk that additional threat actors could repurpose the code against home users and small businesses.
Subsequent intrusions showed Paradise being deployed through suspected exploitation of outdated AweSun remote-control software, alongside activity involving Sunlogin flaws, Sliver C2, Cobalt Strike, BYOVD tooling, and XMRig. In one analyzed case, the ransomware used RSA-1024 encryption, deleted Volume Shadow Copies, set persistence through a Windows Run key, prioritized database and backup paths for encryption, and sent victim metadata to a command-and-control endpoint before dropping a ransom note tied to the email main@paradisenewgenshinimpact.top and a Bitcoin wallet. Defenders were urged to patch exposed remote-access software and maintain endpoint protections to reduce the risk of Paradise deployment.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
A Paradise affiliate distributed the ransomware through an IQY-file spam campaign. The campaign was identified as part of Paradise activity during 2020.
Bitdefender released another decryption tool for Paradise ransomware. The additional decryptor further reduced the effectiveness of Paradise campaigns against victims.
Emsisoft released a free decryption utility for Paradise ransomware, providing victims with a recovery option. This was cited as one factor in the later decline of Paradise activity.
Paradise ransomware was first discovered in 2017 and operated as a ransomware-as-a-service family. The malware was described as primarily targeting home users and smaller companies.
ASEC reported a recent Paradise ransomware intrusion in which the malware was likely installed after exploitation of outdated AweSun remote-control software. The activity was linked to a broader cluster that also used Sunlogin vulnerabilities to deploy Sliver C2, BYOVD tooling, XMRig, and likely Cobalt Strike.
After the leak, Bart Blaze compiled sample Paradise strains from the exposed source code and submitted them to ID-Ransomware. ID-Ransomware classified the resulting samples as undecryptable, highlighting the risk of code reuse by other actors.
The source code for the .NET version of Paradise ransomware, including the builder and decryption utility, was leaked on the Russian-speaking XSS hacking forum. Malware analysts Bart Blaze and MalwareHunterTeam verified the leaked files as authentic.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
labs.bitdefender.com
Open sourceasec.ahnlab.com
Open sourcetherecord.media
Open sourcelastline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.