BI_D Ransomware
- Malware type
- ransomware
- Profile updated
- 2026-07-07 14:49:11
Context
Small and relatively simple ransomware for Windows. Gives files the .BI_D extension after encrypting them with a combination of RSA/AES. Persistence achieved via the Windows Registry. Kills all processes on the victim machine besides itself and a small whitelist of mostly Windows sytem processes and kills shadow copies.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Bid Ransomware (report)
- zirconic.net — Bi D Ransomware (report)
- zirconic.net — Bi D Ransomware Redux Now With 100 More Ghidra (report)