Threat reportRansomwareTL-2026-0086

ZETARINK Ransomware v1.22 — Go-Based File Encryption with Garble Obfuscation and Tor Recovery Portal

mediumDORMANT

ZETARINK Ransomware v1.22 (TL-2026-0086) is a medium-severity ransomware operation, first published 2026-02-15. It has no confirmed attribution, maps to 22 MITRE ATT&CK techniques (T1005, T1027.002, T1027.004), and is covered by 9 detection rules and 23 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
22MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
23Indicators of compromise

Key facts for TL-2026-0086

Threat ID
TL-2026-0086
Severity
MEDIUM
Status
DORMANT
Category
RANSOMWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
Individuals, Small Business, General
Target regions
Global
Detection rules
9
Indicators of compromise
23

Malware and tooling in ZETARINK Ransomware v1.22

Malware and tooling: zetarink

How ZETARINK Ransomware v1.22 works

ZETARINK is a Go-based ransomware (v1.22) obfuscated with Garble that encrypts victim files with a .ZETARINK[random] extension, demands 0.00015 BTC (~$15) via a Tor-based recovery portal, and changes the desktop wallpaper. The unusually low ransom amount suggests a spray-and-pray distribution model targeting individual consumers and small businesses rather than enterprise double-extortion operations.

ZETARINK ransomware v1.22 is a Go-language compiled file encryptor using the Garble obfuscation framework to hinder static analysis and reverse engineering. Upon execution, it encrypts all accessible files appending a .ZETARINK[random_string] extension (e.g., document.pdf becomes document.pdf.ZETARINKXxpV1yCM), generates a ransom note named ZETARINK[random_string]-HOW-TO-DECRYPT.txt, and modifies the desktop wallpaper to display encryption notification.

The ransom note instructs victims to download Tor Browser, navigate to a personal recovery link, enter a unique personal code, and pay 0.00015 BTC to wallet bc1q4vsrn6cwpfxz3y5d4gsp9ksrvl3qrw2fj3ytpm. After payment, an administrator manually verifies the transaction and provides a recovery key and decryptor download link via the Tor portal.

Key technical characteristics: - **Go binary with Garble obfuscation**: Garble is a Go build tool that obfuscates Go binaries by randomizing package paths, function names, and string literals. ESET detects the sample as WinGo/Packed.Obfuscated.D, ClamAV as Win.Tool.Garble-10044180-0, confirming Garble usage. - **Low ransom amount (0.00015 BTC ≈ $15)**: This is orders of magnitude below typical ransomware demands, suggesting either: (a) spray-and-pray targeting consumers, (b) early-stage ransomware by a developing actor, or (c) a testing/proof-of-concept version intended for refinement. - **Tor recovery portal**: Uses a dedicated .onion site with manual administrator payment verification, suggesting a small operation without automated payment processing infrastructure. - **No data exfiltration observed**: Unlike modern double-extortion ransomware, ZETARINK appears to be encryption-only with no evidence of data theft or leak site. - **Version numbering (v1.22)**: Suggests active development with prior iterations.

Distribution vectors include phishing emails with malicious attachments, pirated software and crack/keygen downloads, P2P networks, malicious advertisements, and compromised websites. The ransomware may spread laterally across connected network devices if not isolated promptly.

The Go/Garble combination represents a growing trend in ransomware development — Go provides cross-platform compilation and complex binary structure that complicates analysis, while Garble adds an additional obfuscation layer specifically targeting Go reverse engineering tools.

MITRE ATT&CK techniques used in TL-2026-0086

collection

T1005 Data from Local System

defense-evasion

T1027.002 Software Packing; T1027.004 Compile After Delivery; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

execution

T1059 Command and Scripting Interpreter; T1059.001 PowerShell; T1204.002 Malicious File

command-and-control

T1071.001 Web Protocols; T1090.003 Multi-hop Proxy

discovery

T1082 System Information Discovery; T1083 File and Directory Discovery; T1120 Peripheral Device Discovery; T1135 Network Share Discovery

initial-access

T1189 Drive-by Compromise; T1195.002 Compromise Software Supply Chain; T1566.001 Spearphishing Attachment

impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1491.001 Internal Defacement

persistence

T1547.001 Registry Run Keys / Startup Folder

defense-impairment

T1685 Disable or Modify Tools

Remediation for ZETARINK Ransomware v1.22

Immediate actions

  • Isolate infected system from network immediately to prevent lateral spread
  • Disconnect all external storage devices (USB, NAS) after safe ejection
  • Log out of cloud storage accounts (OneDrive, Dropbox, Google Drive) to prevent cloud sync of encrypted files
  • Do NOT pay the ransom — $15 amount and manual verification suggest unreliable decryptor delivery
  • Preserve ransom note and encrypted file samples for forensic analysis and potential future decryptor development

Workarounds

  • Check ID Ransomware (id-ransomware.malwarehunterteam.com) and No More Ransom (nomoreransom.org) for potential future decryptor availability
  • Use Volume Shadow Copy recovery if ransomware did not delete shadow copies (vssadmin list shadows)
  • Attempt file recovery with forensic data recovery tools on encrypted files
  • Submit samples to AV vendors for detection signature updates

Longer-term hardening

  • Implement 3-2-1 backup strategy: 3 copies, 2 different media, 1 offsite/offline
  • Deploy endpoint detection and response (EDR) capable of detecting Go-based malware and Garble-obfuscated binaries
  • Enable controlled folder access in Windows Defender to protect critical directories from unauthorized encryption
  • Train users on phishing identification — primary distribution vector for ZETARINK
  • Block execution of unsigned binaries and implement application whitelisting
  • Monitor for Tor Browser downloads and .onion traffic as post-infection indicators

Weaknesses (CWE) in ZETARINK Ransomware v1.22

CWE-327

Timeline of ZETARINK Ransomware v1.22

  • ZETARINK ransomware v1.22 development — version number suggests iterative development from earlier versions. Source: Ransom note analysis
  • ZETARINK sample submitted to VirusTotal (SHA256: 904cee06bbc6093213e8653b120b2b72701bac7e8dbfbdd69bfb3aed9b6a7298). Detection by ESET as WinGo/Packed.Obfuscated.D. Source: VirusTotal
  • Multiple AV engines detect ZETARINK: AhnLab (Trojan/Win.MalwareX-gen.R728899), ClamAV (Win.Tool.Garble-10044180-0), Kaspersky (UDS:Trojan.Win32.DelShad.psd), Microsoft (Trojan:Win32/Wacatac.B!ml). Source: VirusTotal
  • PCRisk publishes ZETARINK ransomware removal guide with technical analysis, ransom note text, Tor portal screenshots, and IOCs. Source: PCRisk
  • Threadlinqs Intelligence begins tracking ZETARINK as TL-2026-0086 for full pipeline analysis. Source: Threadlinqs Intelligence
  • As of 2026-05-29, no public evidence of new ZETARINK v1.22 activity, victims, or a successor was found, and this unattributed Go/Garble ransomware shows no resurgence since disclosure. It remains DORMANT, though its builder and Tor recovery portal could be reused (low external corroboration).

Sources cited for ZETARINK Ransomware v1.22

Detection coverage for TL-2026-0086

As of 2026-02-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0086 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
23 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats