BTCWare

First seen
2017-04-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 14:50:52

Context

According to PCRisk, BTCWare is an updated version of a ransomware-type virus called Crptxxx. This ransomware is distributed via a malicious application called "Rogers Hi-Speed Internet". Once infiltrated, BTCWare encrypts files and appends filenames with the ".btcware" extension. Newer variants of this ransomware append .shadow, .payday, .wyvern, .nuclear, .aleta, .gryphon, .nopasaran, .blocking, .xfile, .master, .onyon, .theva, .cryptobyte or .cryptowin extensions to encrypted files. BTCWare then creates an HTM file ("#_HOW_TO_FIX_!.hta.htm"), placing it on the desktop. Other variants of this ransomware use !#_RESTORE_FILES_#!.inf file to store their ransom demanding message.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Btcware_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Btcware (report)
  • bleepingcomputer.com — New Nuclear Btcware Ransomware Released Updated (report)

External references