www.theguardian.com Popcorn Time Ransomware Introduces Pyramid Scheme for Free Decryption
Article Content
- •Popcorn Time ransomware allows victims to avoid ransom by infecting others.
- •The malware may delete files after four incorrect decryption attempts.
- •Experts are skeptical about the effectiveness of the malware's referral strategy.
A new ransomware variant named Popcorn Time has emerged, discovered by MalwareHunterTeam. This malware offers victims a chance to avoid paying a ransom by infecting two other people, who must also pay the ransom for the original victim to receive a free decryption key. The ransomware encrypts files on the victim's computer and demands payment, typically in Bitcoin. If the victim enters the wrong decryption key four times, the ransomware may delete their files, although this feature is still under development. Popcorn Time is currently in the wild, posing a credible threat to users. Security experts are uncertain about the effectiveness of its unique referral mechanism for spreading infections. The malware is not related to the legitimate Popcorn Time streaming application. Users are advised against paying ransoms, as there is no guarantee of file recovery.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Petya in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…