CS-137

CS-137cs-137

Description

Cs‑137 is a newly observed ransomware strain that first appeared in January 2025. It employs the ChaCha20 cipher for encryption and appends obfuscated filenames with a random 10-character alphanumeric identifier while preserving the original file extension. In its current testing phase, it drops a ransom note with a randomized filename (e.g. ABCDEF-README.txt) and sets a randomly named image file as the desktop wallpaper. The note references a Tor-based extortion portal—though access is not yet active, indicating the operation’s early development stage. The strategy suggests single-extortion behavior, focused on disrupting access rather than data theft or leak threats.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
cactus
Software
EncoderCSL
Software
2023lock
Software
CSP
Software
crosslock
Software
CNH
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.