Polyglot is a ransomware variant first documented in June 2017 by researchers at BleepingComputer, belonging to the Jigsaw ransomware family. It is distributed primarily through phishing emails with malicious macro-enabled attachments, targeting individual consumers and small businesses. The threat actor behind Polyglot remains unidentified; the malware’s purpose is file encryption for Bitcoin extortion.
Polyglot encrypts user files using a combination of AES-128 and RSA-1024 algorithms, appending the .polyglot extension to each encrypted file. It achieves persistence by adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware deletes Volume Shadow Copies using vssadmin.exe Delete Shadows /All /Quiet to inhibit recovery. It communicates with a hardcoded C2 server over HTTP to exchange encryption keys; some versions embed keys statically. Evasion techniques include checking for debugger processes (e.g., OllyDbg) and using process hollowing to inject into legitimate executables. Propagation is limited to the initial infection vector; it does not spread laterally via network shares.
Polyglot emerged in mid-2017 as a modified variant of Jigsaw, featuring a new ransom note and altered encryption routine. No high-profile corporate victims have been publicly disclosed; infections were largely limited to home users. No CVEs are associated, as the malware exploits no vulnerabilities—only social engineering. No law enforcement actions specifically targeting Polyglot have been reported.
Known file hashes include SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (example from VirusTotal Polyglot sample). Behavioral indicators include the presence of files with .polyglot extension and a ransom note named “How to decrypt files.txt”. Network IOCs include C2 IP addresses in Eastern Europe (e.g., 185.165.29.x) and User-Agent strings mimicking Mozilla/5.0 (Windows NT 6.1; Win64; x64). Registry modifications under HKCU...Run for persistence, and mutex named “PolyglotMutex” are observed.
Polyglot causes permanent encryption of personal documents, images, and databases without reliable decryption tools, unless victims possess backups. Ransom demands typically range from 0.5 to 1 Bitcoin (approx. $500–$2,000 at time of infection). Affected sectors include individual consumers and small to medium businesses lacking robust backup and security controls.
Mitigation requires maintaining offline backups, deploying email gateway filtering to block macro attachments, and using endpoint detection and response (EDR) solutions with behavioral rules. Users should never pay ransoms and instead restore from backups. No specific patches exist as the malware does not exploit vulnerabilities, but keeping systems updated reduces attack surface from secondary payloads.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.