BI_D Ransomware

Malware type
ransomware
Profile updated
2026-07-07 14:49:11

Context

Small and relatively simple ransomware for Windows. Gives files the .BI_D extension after encrypting them with a combination of RSA/AES. Persistence achieved via the Windows Registry. Kills all processes on the victim machine besides itself and a small whitelist of mostly Windows sytem processes and kills shadow copies.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Bid Ransomware (report)
  • zirconic.net — Bi D Ransomware (report)
  • zirconic.net — Bi D Ransomware Redux Now With 100 More Ghidra (report)

External references