Threat reportRansomwareTL-2026-0086
ZETARINK Ransomware v1.22 — Go-Based File Encryption with Garble Obfuscation and Tor Recovery Portal
ZETARINK Ransomware v1.22 (TL-2026-0086) is a medium-severity ransomware operation, first published 2026-02-15. It has no confirmed attribution, maps to 22 MITRE ATT&CK techniques (T1005, T1027.002, T1027.004), and is covered by 9 detection rules and 23 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 22MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 23Indicators of compromise
Key facts for TL-2026-0086
- Threat ID
- TL-2026-0086
- Severity
- MEDIUM
- Status
- DORMANT
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- Individuals, Small Business, General
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in ZETARINK Ransomware v1.22
Malware and tooling: zetarink
How ZETARINK Ransomware v1.22 works
ZETARINK is a Go-based ransomware (v1.22) obfuscated with Garble that encrypts victim files with a .ZETARINK[random] extension, demands 0.00015 BTC (~$15) via a Tor-based recovery portal, and changes the desktop wallpaper. The unusually low ransom amount suggests a spray-and-pray distribution model targeting individual consumers and small businesses rather than enterprise double-extortion operations.
ZETARINK ransomware v1.22 is a Go-language compiled file encryptor using the Garble obfuscation framework to hinder static analysis and reverse engineering. Upon execution, it encrypts all accessible files appending a .ZETARINK[random_string] extension (e.g., document.pdf becomes document.pdf.ZETARINKXxpV1yCM), generates a ransom note named ZETARINK[random_string]-HOW-TO-DECRYPT.txt, and modifies the desktop wallpaper to display encryption notification.
The ransom note instructs victims to download Tor Browser, navigate to a personal recovery link, enter a unique personal code, and pay 0.00015 BTC to wallet bc1q4vsrn6cwpfxz3y5d4gsp9ksrvl3qrw2fj3ytpm. After payment, an administrator manually verifies the transaction and provides a recovery key and decryptor download link via the Tor portal.
Key technical characteristics: - **Go binary with Garble obfuscation**: Garble is a Go build tool that obfuscates Go binaries by randomizing package paths, function names, and string literals. ESET detects the sample as WinGo/Packed.Obfuscated.D, ClamAV as Win.Tool.Garble-10044180-0, confirming Garble usage. - **Low ransom amount (0.00015 BTC ≈ $15)**: This is orders of magnitude below typical ransomware demands, suggesting either: (a) spray-and-pray targeting consumers, (b) early-stage ransomware by a developing actor, or (c) a testing/proof-of-concept version intended for refinement. - **Tor recovery portal**: Uses a dedicated .onion site with manual administrator payment verification, suggesting a small operation without automated payment processing infrastructure. - **No data exfiltration observed**: Unlike modern double-extortion ransomware, ZETARINK appears to be encryption-only with no evidence of data theft or leak site. - **Version numbering (v1.22)**: Suggests active development with prior iterations.
Distribution vectors include phishing emails with malicious attachments, pirated software and crack/keygen downloads, P2P networks, malicious advertisements, and compromised websites. The ransomware may spread laterally across connected network devices if not isolated promptly.
The Go/Garble combination represents a growing trend in ransomware development — Go provides cross-platform compilation and complex binary structure that complicates analysis, while Garble adds an additional obfuscation layer specifically targeting Go reverse engineering tools.
MITRE ATT&CK techniques used in TL-2026-0086
collection
defense-evasion
T1027.002 Software Packing; T1027.004 Compile After Delivery; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
execution
T1059 Command and Scripting Interpreter; T1059.001 PowerShell; T1204.002 Malicious File
command-and-control
T1071.001 Web Protocols; T1090.003 Multi-hop Proxy
discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1120 Peripheral Device Discovery; T1135 Network Share Discovery
initial-access
T1189 Drive-by Compromise; T1195.002 Compromise Software Supply Chain; T1566.001 Spearphishing Attachment
impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1491.001 Internal Defacement
persistence
T1547.001 Registry Run Keys / Startup Folder
defense-impairment
Remediation for ZETARINK Ransomware v1.22
Immediate actions
- Isolate infected system from network immediately to prevent lateral spread
- Disconnect all external storage devices (USB, NAS) after safe ejection
- Log out of cloud storage accounts (OneDrive, Dropbox, Google Drive) to prevent cloud sync of encrypted files
- Do NOT pay the ransom — $15 amount and manual verification suggest unreliable decryptor delivery
- Preserve ransom note and encrypted file samples for forensic analysis and potential future decryptor development
Workarounds
- Check ID Ransomware (id-ransomware.malwarehunterteam.com) and No More Ransom (nomoreransom.org) for potential future decryptor availability
- Use Volume Shadow Copy recovery if ransomware did not delete shadow copies (vssadmin list shadows)
- Attempt file recovery with forensic data recovery tools on encrypted files
- Submit samples to AV vendors for detection signature updates
Longer-term hardening
- Implement 3-2-1 backup strategy: 3 copies, 2 different media, 1 offsite/offline
- Deploy endpoint detection and response (EDR) capable of detecting Go-based malware and Garble-obfuscated binaries
- Enable controlled folder access in Windows Defender to protect critical directories from unauthorized encryption
- Train users on phishing identification — primary distribution vector for ZETARINK
- Block execution of unsigned binaries and implement application whitelisting
- Monitor for Tor Browser downloads and .onion traffic as post-infection indicators
Weaknesses (CWE) in ZETARINK Ransomware v1.22
Timeline of ZETARINK Ransomware v1.22
- ZETARINK ransomware v1.22 development — version number suggests iterative development from earlier versions. Source: Ransom note analysis
- ZETARINK sample submitted to VirusTotal (SHA256: 904cee06bbc6093213e8653b120b2b72701bac7e8dbfbdd69bfb3aed9b6a7298). Detection by ESET as WinGo/Packed.Obfuscated.D. Source: VirusTotal
- Multiple AV engines detect ZETARINK: AhnLab (Trojan/Win.MalwareX-gen.R728899), ClamAV (Win.Tool.Garble-10044180-0), Kaspersky (UDS:Trojan.Win32.DelShad.psd), Microsoft (Trojan:Win32/Wacatac.B!ml). Source: VirusTotal
- PCRisk publishes ZETARINK ransomware removal guide with technical analysis, ransom note text, Tor portal screenshots, and IOCs. Source: PCRisk
- Threadlinqs Intelligence begins tracking ZETARINK as TL-2026-0086 for full pipeline analysis. Source: Threadlinqs Intelligence
- As of 2026-05-29, no public evidence of new ZETARINK v1.22 activity, victims, or a successor was found, and this unattributed Go/Garble ransomware shows no resurgence since disclosure. It remains DORMANT, though its builder and Tor recovery portal could be reused (low external corroboration).
Sources cited for ZETARINK Ransomware v1.22
Detection coverage for TL-2026-0086
As of 2026-02-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0086 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.