Researchers analyzed Polyglot, a ransomware family distributed through spam emails that directed victims to malicious RAR archives, and found it was designed to closely imitate CTB-Locker. The malware copied CTB-Locker’s interface, ransom workflow, Bitcoin payment model, and cryptographic presentation, while operating as an independently developed threat rather than a code-sharing variant. Once executed, Polyglot encrypted files without renaming them, established persistence through autostart entries and Task Scheduler, and communicated with a Tor-based command-and-control infrastructure via a public tor2web service.
The investigation found critical implementation flaws in Polyglot’s random number generation and ZIP password derivation, allowing encrypted files to be recovered without paying the ransom. Based on those weaknesses, researchers said victims could restore data using Kaspersky Lab’s free RannohDecryptor utility, version 1.9.3.0, turning what appeared to be a convincing CTB-Locker-style extortion campaign into a ransomware operation with an available public decryption path.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Polyglot, a ransomware family masquerading as CTB-Locker, emerged in late August and was distributed through spam emails linking to malicious RAR archives.
Because of the identified implementation flaws, files encrypted by Polyglot could be recovered using Kaspersky Lab's free RannohDecryptor utility version 1.9.3.0.
Analysis of Polyglot found flaws in its random number generation and ZIP password derivation that made recovery of encrypted files feasible. The researchers also concluded Polyglot imitated CTB-Locker but was developed independently rather than sharing its codebase.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.