HiddenTear is an open-source proof-of-concept ransomware family for Microsoft Windows that became widely reused and adapted by criminal actors after its public release. Although presented as educational code, it has served as the basis for numerous real-world ransomware variants and derivative families, lowering the barrier to entry for less sophisticated operators and enabling rapid creation of custom extortion malware.
HiddenTear is designed to encrypt victim files and demand payment for decryption. Public reporting and malware analyses link it to many repurposed strains, including variants used in themed phishing campaigns and later ransomware families such as Ranion and Sorry HT. Derivatives and samples bearing HiddenTear signatures have also appeared in broader criminal infrastructure, including command-and-control ecosystems associated with financially motivated actors. In some observed cases, samples carrying HiddenTear signatures did not proceed to encrypt files during sandbox execution, indicating that signature overlap, incomplete builds, or repurposed artifacts can occur.
The family primarily targets Windows systems and is commonly associated with file encryption behavior, ransom-note deployment, and straightforward implementation patterns that make it attractive for modification. Analyses of HiddenTear-derived samples have also documented common commodity-malware enhancements such as obfuscation, packing, anti-debugging, self-deletion, and process hollowing or RunPE-style execution in some variants. Delivery has been observed through malicious documents in phishing campaigns, including socially engineered lures such as COVID-19-themed messages, while the source code has also been incorporated into ransomware-as-a-service and other derivative operations.
HiddenTear is significant less for technical sophistication than for its ecosystem impact. Its public availability helped normalize reuse of open ransomware code, and it is frequently cited as a canonical example of how proof-of-concept extortion malware can be operationalized at scale by unrelated threat actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
No less than 31,000 malware samples, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT, and artifacts bearing HiddenTear ransomware signatures, have communicated with Sable Squirrel's infrastructure.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Loading the binary into JustDecompileIt we notice that it was crypted by something called Aika. The Assembly Information also gives away that ConfuserEx is involved as well.
"A subset of these same domains also operate as malware C2. We identified over 31,000 malware samples connecting to Sable Squirrel domains... In such cases, a human visitor sees a live football streaming site while an infected device uses the same domain as a control channel."
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware referenced as using repurposed expired domains as command-and-control/supporting infrastructure.
Ransomware family whose signatures were found among malware samples communicating with Sable Squirrel infrastructure.
Ransomware family whose signatures were found in malware samples communicating with Sable Squirrel domain infrastructure.
Ransomware family/signature observed in samples using Sable Squirrel infrastructure; the report does not confirm successful file encryption in the wild.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.