Polyglot
Malware⚠️ Overview
Polyglot is a ransomware variant first documented in June 2017 by researchers at BleepingComputer, belonging to the Jigsaw ransomware family. It is distributed primarily through phishing emails with malicious macro-enabled attachments, targeting individual consumers and small businesses. The threat actor behind Polyglot remains unidentified; the malware’s purpose is file encryption for Bitcoin extortion.
🔧 Technical Capabilities
Polyglot encrypts user files using a combination of AES-128 and RSA-1024 algorithms, appending the .polyglot extension to each encrypted file. It achieves persistence by adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware deletes Volume Shadow Copies using vssadmin.exe Delete Shadows /All /Quiet to inhibit recovery. It communicates with a hardcoded C2 server over HTTP to exchange encryption keys; some versions embed keys statically. Evasion techniques include checking for debugger processes (e.g., OllyDbg) and using process hollowing to inject into legitimate executables. Propagation is limited to the initial infection vector; it does not spread laterally via network shares.
📜 History & Notable Incidents
Polyglot emerged in mid-2017 as a modified variant of Jigsaw, featuring a new ransom note and altered encryption routine. No high-profile corporate victims have been publicly disclosed; infections were largely limited to home users. No CVEs are associated, as the malware exploits no vulnerabilities—only social engineering. No law enforcement actions specifically targeting Polyglot have been reported.
🔍 Detection Indicators
Known file hashes include SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (example from VirusTotal Polyglot sample). Behavioral indicators include the presence of files with .polyglot extension and a ransom note named “How to decrypt files.txt”. Network IOCs include C2 IP addresses in Eastern Europe (e.g., 185.165.29.x) and User-Agent strings mimicking Mozilla/5.0 (Windows NT 6.1; Win64; x64). Registry modifications under HKCU...Run for persistence, and mutex named “PolyglotMutex” are observed.
☠️ Risk & Impact
Polyglot causes permanent encryption of personal documents, images, and databases without reliable decryption tools, unless victims possess backups. Ransom demands typically range from 0.5 to 1 Bitcoin (approx. $500–$2,000 at time of infection). Affected sectors include individual consumers and small to medium businesses lacking robust backup and security controls.
🛡️ Mitigation
Mitigation requires maintaining offline backups, deploying email gateway filtering to block macro attachments, and using endpoint detection and response (EDR) solutions with behavioral rules. Users should never pay ransoms and instead restore from backups. No specific patches exist as the malware does not exploit vulnerabilities, but keeping systems updated reduces attack surface from secondary payloads.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.