cs-137

First seen
2025-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:54:54

Context

Cs‑137 is a newly observed ransomware strain that first appeared in January 2025. It employs the ChaCha20 cipher for encryption and appends obfuscated filenames with a random 10-character alphanumeric identifier while preserving the original file extension. In its current testing phase, it drops a ransom note with a randomized filename (e.g. ABCDEF-README.txt) and sets a randomly named image file as the desktop wallpaper. The note references a Tor-based extortion portal—though access is not yet active, indicating the operation’s early development stage. The strategy suggests single-extortion behavior, focused on disrupting access rather than data theft or leak threats.

Reports & references

  • ransomlook.io — Cs 137 (report)
  • watchguard.com — Cs 137 (report)

External references