ToxicEye
- First seen
- 2021-04-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:55:25
- Profile updated
- 2026-07-07 15:23:23
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical
Context
ToxicEye is a ransomware that spreads through phishing emails. The malware encrypts system files with AES-256 and demands a ransom in Bitcoin.
Detection coverage
- 1 YARA rules
Detection rules
- SIGNATURE_BASE_HKTL_NET_GUID_Toxiceye (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Toxiceye (report)
- bollyinside.com — How Rat Malware Is Using Telegram To Evade Detection (report)
- github.com — Toxiceyerat (report)
- blog.checkpoint.com — Turning Telegram Toxic New Toxiceye Rat Is The Latest To Use Telegram For Command Control (report)