TYRANT
Aliases: Crypto Tyrant
- First seen
- 2017-11-16 00:00:00
- Malware type
- ransomware
- Profile updated
- 2026-07-07 13:41:43
Targeted regions: country_code:ir
Context
DUMB variant discovered on November 16, 2017. Disguised itself as a popular virtual private network (VPN) in Iran known as Psiphon and infected Iranian users. Included Farsi-language ransom note, decryptable in the same way as previous DUMB-based variants. Message requested only US$15 for unlock key. Advertised two local and Iran-based payment processors: exchange.ir and webmoney.ir.Shared unique and specialized indicators with RASTAKHIZ; iDefense threat intelligence analysts believe this similarity confirms that the same actor was behind the repurposing of both types of ransomware.
Reports & references
- accenture.com — Accenture Cyber Threatscape Report 2018 (report)
- id-ransomware.blogspot.com — Tyrant Ransomware (report)