WeChat Ransom

Aliases: UNNAMED1989

First seen
2018-12-01 00:00:00
Malware type
ransomware, credential-stealer
Profile updated
2026-07-07 13:43:07

Targeted industries: technology-and-telecommunications

Targeted regions: country_code:cn

Context

Over 100,000 thousand computers in China have been infected in just a few days with poorly-written ransomware that encrypts local files and steals credentials for multiple Chinese online services. The crooks show a screen titled UNNAMED1989 and demand the victim a ransom of 110 yuan ($16) in exchange for decrypting the files, payable via Tencent's WeChat payment service by scanning a QR code.

Reports & references

  • bleepingcomputer.com — Ransomware Infects 100K Pcs In China Demands Wechat Payment (report)
  • bleepingcomputer.com — Chinese Police Arrest Dev Behind Unnamed1989 Wechat Ransomware (report)

External references