Researchers reported that the KeyPass ransomware was actively distributed through fake software installers that fetched and launched the payload on Windows systems. The C++ malware copied itself into %LocalAppData%, deleted the original file, and spawned child processes using command-line arguments containing the victim ID and encryption key. It then encrypted files on local disks and reachable network shares, appended the .KEYPASS extension, and dropped ransom notes named !!!KEYPASS_DECRYPTION_INFO!!!.txt across affected directories.
Analysis showed that KeyPass used AES-256 in CFB mode with a zero IV and encrypted roughly the first 5 MB of each targeted file. The malware requested the encryption key and victim identifier from a command-and-control server over plain HTTP JSON, but if the server was unavailable it reverted to a hardcoded key and ID, leaving offline-encrypted files easily recoverable. Researchers also identified a hidden GUI that could be exposed with a special keypress, indicating the operators built in support for manual control and customizable encryption behavior.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Securelist published a technical analysis detailing KeyPass behavior, including its encryption routine, command-and-control communications, hidden GUI, and the weakness in its offline encryption fallback. The report also shared indicators of compromise including a sample hash and C2 URL.
Securelist reported that the KeyPass ransomware variant began spreading actively in August through fake installers that downloaded the ransomware payload. The report described this as a newly detected campaign observed by Securelist and others in the security community.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.