#chacha20 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #chacha20, aggregated by home.social.
-
Multi-Functional Linux Botnet "Evooo1Bot"
A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.
Pulse ID: 6a7e2be6ba37cc87ae552659
Pulse Link: https://otx.alienvault.com/pulse/6a7e2be6ba37cc87ae552659
Pulse Author: AlienVault
Created: 2026-08-13 20:41:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault
-
Multi-Functional Linux Botnet "Evooo1Bot"
A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.
Pulse ID: 6a7e2be6ba37cc87ae552659
Pulse Link: https://otx.alienvault.com/pulse/6a7e2be6ba37cc87ae552659
Pulse Author: AlienVault
Created: 2026-08-13 20:41:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault
-
Recent Attack Activity Analysis Using North Korea-Related Lures
APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.
Pulse ID: 6a7dc1fd395815126acd4647
Pulse Link: https://otx.alienvault.com/pulse/6a7dc1fd395815126acd4647
Pulse Author: AlienVault
Created: 2026-08-13 13:09:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault
-
Recent Attack Activity Analysis Using North Korea-Related Lures
APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.
Pulse ID: 6a7dc1fd395815126acd4647
Pulse Link: https://otx.alienvault.com/pulse/6a7dc1fd395815126acd4647
Pulse Author: AlienVault
Created: 2026-08-13 13:09:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault
-
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...
Pulse ID: 6a7a12d2aa28d8347ab323f6
Pulse Link: https://otx.alienvault.com/pulse/6a7a12d2aa28d8347ab323f6
Pulse Author: AlienVault
Created: 2026-08-10 18:05:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault
-
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...
Pulse ID: 6a7a12d2aa28d8347ab323f6
Pulse Link: https://otx.alienvault.com/pulse/6a7a12d2aa28d8347ab323f6
Pulse Author: AlienVault
Created: 2026-08-10 18:05:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault
-
Toy Ghouls’ new toy: the GenieLocker ransomware
GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.
Pulse ID: 6a6b1c3ea08dbc663eb8f4c0
Pulse Link: https://otx.alienvault.com/pulse/6a6b1c3ea08dbc663eb8f4c0
Pulse Author: AlienVault
Created: 2026-07-30 09:41:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #ELF #Encryption #InfoSec #Linux #LockBit #Manufacturing #OTX #OpenThreatExchange #PsExec #RAT #RansomWare #Russia #Rust #SSH #UK #VPN #Windows #bot #AlienVault
-
Toy Ghouls’ new toy: the GenieLocker ransomware
GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.
Pulse ID: 6a6b1c3ea08dbc663eb8f4c0
Pulse Link: https://otx.alienvault.com/pulse/6a6b1c3ea08dbc663eb8f4c0
Pulse Author: AlienVault
Created: 2026-07-30 09:41:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #ELF #Encryption #InfoSec #Linux #LockBit #Manufacturing #OTX #OpenThreatExchange #PsExec #RAT #RansomWare #Russia #Rust #SSH #UK #VPN #Windows #bot #AlienVault
-
GoSerpent backdoor attacks in Southeast Asia
Since late 2025, government and diplomatic entities in Southeast Asia have been targeted by sophisticated attacks involving GoSerpent, a Go-based RAT with proxy capabilities. The malware receives encrypted arguments and deploys additional tools for data collection and credential dumping. GoSerpent has been active since 2021, with newer variants using AES-CBC encryption and ChaCha20 for communications. The campaign involves multiple stages: initial deployment of GoSerpent and ThumbcacheService to collect sensitive files, credential dumping via Mimikatz and QuarksDumpLocalHash, followed by deployment of Stowaway RAT in May 2026 and TmcLoader/TmcPayload for stealthy data exfiltration through network shares. The integrated toolset demonstrates sophisticated operational planning, with attackers leveraging Alibaba Cloud and UCLOUD HK infrastructure while exhibiting possible connections to the TetrisPhantom threat actor.
Pulse ID: 6a590384cb730e14eaafeac5
Pulse Link: https://otx.alienvault.com/pulse/6a590384cb730e14eaafeac5
Pulse Author: AlienVault
Created: 2026-07-16 16:15:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #ChaCha20 #Cloud #CyberSecurity #Encryption #Government #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #bot #AlienVault
-
GoSerpent backdoor attacks in Southeast Asia
Since late 2025, government and diplomatic entities in Southeast Asia have been targeted by sophisticated attacks involving GoSerpent, a Go-based RAT with proxy capabilities. The malware receives encrypted arguments and deploys additional tools for data collection and credential dumping. GoSerpent has been active since 2021, with newer variants using AES-CBC encryption and ChaCha20 for communications. The campaign involves multiple stages: initial deployment of GoSerpent and ThumbcacheService to collect sensitive files, credential dumping via Mimikatz and QuarksDumpLocalHash, followed by deployment of Stowaway RAT in May 2026 and TmcLoader/TmcPayload for stealthy data exfiltration through network shares. The integrated toolset demonstrates sophisticated operational planning, with attackers leveraging Alibaba Cloud and UCLOUD HK infrastructure while exhibiting possible connections to the TetrisPhantom threat actor.
Pulse ID: 6a590384cb730e14eaafeac5
Pulse Link: https://otx.alienvault.com/pulse/6a590384cb730e14eaafeac5
Pulse Author: AlienVault
Created: 2026-07-16 16:15:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #ChaCha20 #Cloud #CyberSecurity #Encryption #Government #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #bot #AlienVault
-
Szyfrowanie danych, usuwanie backupów, zacieranie śladów… analiza ransomware Dire Wolf
Dire Wolf jest nową grupą przestępczą, której aktywność zaobserwowano w maju br. Pierwszymi ofiarami cyberprzestępców były firmy z sektora technologicznego, finansowego oraz budownictwa działające we Włoszech, Tajlandii, Australii oraz Indii. Działania cyberprzestępców ukierunkowane są głównie na zysk finansowy. W celu zwiększenia szansy na uzyskanie okupu, wykorzystują technikę double extortion, grożąc...
#Teksty #Chacha20 #Curbe25519 #Direwolf #DoubleExtortion #Ransomware
-
Szyfrowanie danych, usuwanie backupów, zacieranie śladów… analiza ransomware Dire Wolf
Dire Wolf jest nową grupą przestępczą, której aktywność zaobserwowano w maju br. Pierwszymi ofiarami cyberprzestępców były firmy z sektora technologicznego, finansowego oraz budownictwa działające we Włoszech, Tajlandii, Australii oraz Indii. Działania cyberprzestępców ukierunkowane są głównie na zysk finansowy. W celu zwiększenia szansy na uzyskanie okupu, wykorzystują technikę double extortion, grożąc...
#Teksty #Chacha20 #Curbe25519 #Direwolf #DoubleExtortion #Ransomware
-
Interesting development of ransomware, however I find the title misleading as AES-256 isn't really "stronger" than ChaCha20: https://www.bleepingcomputer.com/news/security/new-qilin-ransomware-encryptor-features-stronger-encryption-evasion/
-
[Перевод] ChaCha, модификация Salsa20
ChaCha8 это 256-битный поточный шифр, основанный на 8-раунодовом шифре Salsa20/8. Новшества, привнесенные при работе от Salsa20/8 до ChaCha8, позволили улучшить перемежение бит за раунд, тем самым повысив стойкость к криптоанализу при сохранении, а иногда и уменьшении, времени требуемого на вычисления одного раунда. ChaCha12 и ChaCha20 являются аналогичными модификациями 12-раундового и 20-раундового шифров Salsa20/12 и Salsa20/20. В данной статье описывается семейство шифров ChaCha и объясняется разница между Salsa20 и ChaCha.
https://habr.com/ru/articles/784452/
#chacha20 #daniel_j_bernstein #перевод #перевод_с_английского
-
[DE] Ein bisschen Krikelkrakel für einen Kurzvortrag zu @rosenpass und postquantensicherer Kryptografie. Im Safe sind natürlich die sichersten Verfahren gegen regnerische post-quanten-Tage. :)
[EN] A handful of chicken scratch for a short talk about #RosenPass and post-quantum secure cryptography. When quantum computers finally rain down on our information systems, there’s different levels of security you can have.
-
[DE] Ein bisschen Krikelkrakel für einen Kurzvortrag zu @rosenpass und postquantensicherer Kryptografie. Im Safe sind natürlich die sichersten Verfahren gegen regnerische post-quanten-Tage. :)
[EN] A handful of chicken scratch for a short talk about #RosenPass and post-quantum secure cryptography. When quantum computers finally rain down on our information systems, there’s different levels of security you can have.
-
CW: research review
S. Dey et al., "Cryptanalysis of Reduced Round ChaCha- New Attack and Deeper Analysis"¹
In this paper we present several analyses on ChaCha, a software stream cipher. First, we consider a divide-and-conquer approach on the secret key bits by partitioning them. The partitions are based on multiple input-output differentials to obtain a significantly improved attack on 6-round ChaCha256 with a complexity of 2^{99.48}. It is 2^{40} times faster than the currently best known attack. Note that, this is the first time an attack could be mounted on reduced round ChaCha with a complexity significantly less than 2^{k}{2}, where the secret key is of k bits. Further, we note that all the attack complexities related to ChaCha are theoretically estimated in general and there are several questions in this regard as pointed out by Dey et al. in Eurocrypt 2022. In this regard, we propose a toy version of ChaCha, with a 32-bit secret key, on which the attacks can be implemented completely to verify whether the theoretical estimates are justified. This idea is implemented for our proposed attack on 6 rounds. Finally, we show that it is possible to estimate the success probabilities of these kinds of PNB-based differential attacks more accurately. Our methodology explains how different cryptanalytic results can be evaluated with better accuracy rather than claiming (Aumasson et al., 2008) that the success probability is significantly better than 50%.
#IACR #ResearchPapers #ARX #ChaCha20 #ProbabilisticNeutralBits #Cryptanalysis #DifferentialAttack #Cryptography
__
¹ https://eprint.iacr.org/2023/134 -
Best practice for sharing encrypted data between server and client
https://security.stackexchange.com/questions/267673/best-practice-for-sharing-encrypted-data-between-server-and-client
#encryption #chacha20 #rsa -
Best practice for sharing encrypted data between server and client
https://security.stackexchange.com/questions/267673/best-practice-for-sharing-encrypted-data-between-server-and-client
#encryption #chacha20 #rsa -
Which do you consider to be more secure?
(Yes, I understand that the symmetric cipher itself is almost never the weak point in any modern cryptosystem)
-
Which do you consider to be more secure?
(Yes, I understand that the symmetric cipher itself is almost never the weak point in any modern cryptosystem)
-
ChaCha20 Encryption Performance on DEC PDP-11/40 https://niconiconi.neocities.org/posts/chacha20-performance-on-pdp-11/ #retrocomputing #PDP11 #ChaCha20 #cryptography
Just started a new homepage and posted my first article.
-
This is a fine year for a crypto dance party
-
RFC 8439: ChaCha20 and Poly1305 for IETF Protocols
Ce #RFC normalise les algorithmes de #cryptographie #ChaCha20 et #Poly1305.