Hidden Tear is an open-source ransomware family released in 2015 as an educational proof of concept and subsequently widely abused by threat actors as the basis for numerous real-world ransomware variants. It is a .NET/C# file-encrypting malware strain that uses AES to encrypt victim files, writes a ransom note, and transmits encryption material and basic host information to a remote server. The codebase includes configurable target file extensions and can be readily modified, which has made it a common foundation for derivative ransomware used in opportunistic and targeted intrusions.
Hidden Tear is notable less for technical sophistication than for its influence on the ransomware ecosystem. Multiple later families and one-off campaigns have been assessed as heavily based on or directly derived from its source code, including variants used in COVID-19-themed phishing operations, campaigns targeting Brazilian users, and bespoke ransomware deployed during broader post-compromise activity. Analysts have repeatedly identified code reuse through shared function structure, encryption logic, and residual project artifacts. Because the source was publicly available, minor edits to strings, ransom notes, target paths, extensions, and network configuration were often sufficient for actors to generate new variants and evade simple signature- or hash-based detections.
Operationally, Hidden Tear and its descendants have been associated with a wide range of actors, from novice criminals to more established intrusion operators. It has appeared in commodity ransomware campaigns, enterprise-targeting incidents, and hands-on-keyboard intrusions where publicly available ransomware was used as a final-stage encryption tool. The family has also been referenced in reporting on actors possessing or deploying public ransomware tooling alongside custom malware and legitimate encryption utilities.
Hidden Tear primarily targets Windows systems. Its historical significance lies in lowering the barrier to entry for ransomware development by providing functional, modifiable source code that accelerated the proliferation of copycat ransomware and derivative extortion malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On April 29, CVE-2026-41940 was disclosed: a critical pre-authentication bypass in cPanel/WHM that lets remote attackers skip the login flow entirely and gain elevated access. Within 24 hours, it was already being weaponized.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
今回確認された「AngleWare」も、その「Hidden Tear」のコードを流用した亜種であるという事実を弊社解析チームは実際のコードを比較調査することにより把握することができました。
9 distinct techniques documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An early ransomware tool cited as easy to detect and flawed in implementation, resulting in lower impact and easier decryption; it primarily targeted regular consumers rather than large organizations.
Open-source ransomware used by a probable CARBON SPIDER actor post-Colonial Pipeline, likely to reduce attention; associated with Demux, Sekur RAT, and Cobalt Strike usage for access/persistence.
An earlier ransomware family/codebase that [F]Unicorn is said to be heavily based on, with some modifications to components such as the panel and HTML/CSS.
Open-source ransomware project originally created for educational purposes; referenced as related to EDA2 and abused by threat actors to build/derive ransomware strains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.