Last seven days
- First activity
- Aug 29, 2026
- Last activity
- Sep 3, 2026
- Feed role
- C2 / Distribution
- Host form
- 6 IP / 0 hostnames
HiddenTear is an open-source proof-of-concept ransomware family for Microsoft Windows that became widely reused and adapted by criminal actors after its public release.
Profile source: Mallory opens in a new tabHiddenTear
HiddenTear is an open-source proof-of-concept ransomware family for Microsoft Windows that became widely reused and adapted by criminal actors after its public release. Although presented as educational code, it has served as the basis for numerous real-world ransomware variants and derivative families, lowering the barrier to entry for less sophisticated operators and enabling rapid creation of custom extortion malware.
HiddenTear is designed to encrypt victim files and demand payment for decryption. Public reporting and malware analyses link it to many repurposed strains, including variants used in themed phishing campaigns and later ransomware families such as Ranion and Sorry HT. Derivatives and samples bearing HiddenTear signatures have also appeared in broader criminal infrastructure, including command-and-control ecosystems associated with financially motivated actors. In some observed cases, samples carrying HiddenTear signatures did not proceed to encrypt files during sandbox execution, indicating that signature overlap, incomplete builds, or repurposed artifacts can occur.
The family primarily targets Windows systems and is commonly associated with file encryption behavior, ransom-note deployment, and straightforward implementation patterns that make it attractive for modification. Analyses of HiddenTear-derived samples have also documented common commodity-malware enhancements such as obfuscation, packing, anti-debugging, self-deletion, and process hollowing or RunPE-style execution in some variants. Delivery has been observed through malicious documents in phishing campaigns, including socially engineered lures such as COVID-19-themed messages, while the source code has also been incorporated into ransomware-as-a-service and other derivative operations.
HiddenTear is significant less for technical sophistication than for its ecosystem impact. Its public availability helped normalize reuse of open ransomware code, and it is frequently cited as a canonical example of how proof-of-concept extortion malware can be operationalized at scale by unrelated threat actors.
C2 tracking
Derp observations, rolling seven-day window
Samples
0f78a658b60f0879acccf0933d9ae8a5d2c188e9f16b8e6f7b01bd0cc9b5c4e1 27215e26b312b8b4f8fc51bdcea6741536dafc9267348284e2259e798aed0e4d 3755718db9d33f4aba2563de454d4530a308b41b1096c904102d08e2101f2020 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 738eacc140159cd81dff41dd16c806eb7c0c8391c256f1738d75d0321f77ba2e Reported operators
No less than 31,000 malware samples, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT, and artifacts bearing HiddenTear ransomware signatures, have communicated with Sable Squirrel's infrastructure.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.