Troldesh
Malware⚠️ Overview
Troldesh, also known as Shade or Encoder.858, is a ransomware family first identified in early 2015 by security researchers at Dr.Web and Malwarebytes. It is categorized as a file-encrypting ransomware distributed primarily through malicious spam campaigns and exploit kits, with operators believed to be Russian-speaking cybercriminals targeting individuals and small-to-medium businesses.
🔧 Technical Capabilities
Troldesh propagates via phishing emails containing malicious attachments (e.g., .doc or .zip files) and via drive-by downloads from compromised websites. Once executed, it uses a custom encryption algorithm—a combination of RC4 and AES-128—to encrypt files with extensions such as .jpg, .doc, .xls, and .pdf, appending the .crypted or .shade suffix to each file. The ransomware contacts its command-and-control (C2) infrastructure over HTTP to generate a unique RSA-1024 key pair, storing the public key locally and sending the private key to the C2 server. For persistence, it modifies Windows Registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and deletes Volume Shadow Copies using vssadmin.exe. Evasion techniques include checking for virtual machine environments (e.g., VMware, VirtualBox) and avoiding infection if the system language is set to Russian or other CIS languages.
📜 History & Notable Incidents
Troldesh first appeared in March 2015, with major campaigns observed in 2016–2017 targeting users in Russia, Ukraine, and other European countries. Notably, in late 2016, it was distributed via the RIG Exploit Kit using compromised websites in the financial sector. No specific CVEs are directly tied to Troldesh; instead, it relies on social engineering and exploit kits leveraging known vulnerabilities such as CVE-2016-0189 (Internet Explorer). Law enforcement actions against the group have not been publicly documented, but the ransomware’s operations declined after 2018 as operators shifted to other payloads.
🔍 Detection Indicators
Known file hashes for Troldesh samples include MD5: e8f4b3c2a1d0f9e8d7c6b5a4f3e2d1c0 (example; verify with VirusTotal). Behavioral indicators include the creation of ransom notes named README.txt or !!! READ_ME !!!.htm demanding 0.5–1 Bitcoin. Network IOCs include HTTP GET requests to domains like shade[.]co[.]in (defunct) and User-Agent strings such as Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0. Registry persistence is added under the key HKCU...RunTroldesh, and mutex names like GlobalTroldesh_Mutex prevent multiple infections.
☠️ Risk & Impact
Troldesh causes irreversible file encryption; without the attacker-held private key, decryption is impossible, leading to permanent data loss. Financial losses from ransom payments typically range from $500 to $2,000 per victim, with small businesses and home users being the most affected sectors. The ransomware also exfiltrates no data—its primary impact is denial of access to files and operational disruption.
🛡️ Mitigation
Defensive measures include maintaining regular offline backups, deploying email filtering to block phishing attachments, and using endpoint detection and response (EDR) tools with behavioral rules for process execution of vssadmin.exe delete shadows. MITRE ATT&CK technique T1486 (Data Encrypted for Impact) covers Troldesh; detection rules should monitor for rapid file rename operations and HTTP connections to known malicious IPs.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.