# ZETARINK Ransomware v1.22 — Go-Based File Encryption with Garble Obfuscation and Tor Recovery Portal

> ZETARINK is a Go-based ransomware (v1.22) obfuscated with Garble that encrypts victim files with a .ZETARINK[random] extension, demands 0.00015 BTC (~$15) via a Tor-based recovery portal, and changes the desktop wallpaper. The unusually low ransom amount suggests a spray-and-pray distribution model targeting individual consumers and small businesses rather than enterprise double-extortion operations.

- **Published:** 2026-02-15T05:17:03Z
- **Last reviewed:** 2026-02-15T05:17:03Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0086
- **ID:** TL-2026-0086
- **Severity:** MEDIUM
- **Category:** RANSOMWARE
- **Status:** DORMANT
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)

## Description

ZETARINK ransomware v1.22 is a Go-language compiled file encryptor using the Garble obfuscation framework to hinder static analysis and reverse engineering. Upon execution, it encrypts all accessible files appending a .ZETARINK[random_string] extension (e.g., document.pdf becomes document.pdf.ZETARINKXxpV1yCM), generates a ransom note named ZETARINK[random_string]-HOW-TO-DECRYPT.txt, and modifies the desktop wallpaper to display encryption notification.

The ransom note instructs victims to download Tor Browser, navigate to a personal recovery link, enter a unique personal code, and pay 0.00015 BTC to wallet bc1q4vsrn6cwpfxz3y5d4gsp9ksrvl3qrw2fj3ytpm. After payment, an administrator manually verifies the transaction and provides a recovery key and decryptor download link via the Tor portal.

Key technical characteristics:
- **Go binary with Garble obfuscation**: Garble is a Go build tool that obfuscates Go binaries by randomizing package paths, function names, and string literals. ESET detects the sample as WinGo/Packed.Obfuscated.D, ClamAV as Win.Tool.Garble-10044180-0, confirming Garble usage.
- **Low ransom amount (0.00015 BTC ≈ $15)**: This is orders of magnitude below typical ransomware demands, suggesting either: (a) spray-and-pray targeting consumers, (b) early-stage ransomware by a developing actor, or (c) a testing/proof-of-concept version intended for refinement.
- **Tor recovery portal**: Uses a dedicated .onion site with manual administrator payment verification, suggesting a small operation without automated payment processing infrastructure.
- **No data exfiltration observed**: Unlike modern double-extortion ransomware, ZETARINK appears to be encryption-only with no evidence of data theft or leak site.
- **Version numbering (v1.22)**: Suggests active development with prior iterations.

Distribution vectors include phishing emails with malicious attachments, pirated software and crack/keygen downloads, P2P networks, malicious advertisements, and compromised websites. The ransomware may spread laterally across connected network devices if not isolated promptly.

The Go/Garble combination represents a growing trend in ransomware development — Go provides cross-platform compilation and complex binary structure that complicates analysis, while Garble adds an additional obfuscation layer specifically targeting Go reverse engineering tools.

## MITRE ATT&CK

- T1204.002 Malicious File
- T1059 Command and Scripting Interpreter
- T1027.002 Software Packing
- T1027.004 Compile After Delivery
- T1036 Masquerading
- T1140 Deobfuscate/Decode Files or Information
- T1083 File and Directory Discovery
- T1082 System Information Discovery
- T1135 Network Share Discovery
- T1486 Data Encrypted for Impact
- T1490 Inhibit System Recovery
- T1491.001 Internal Defacement
- T1566.001 Spearphishing Attachment
- T1189 Drive-by Compromise
- T1090.003 Multi-hop Proxy
- T1071.001 Web Protocols
- T1547.001 Registry Run Keys / Startup Folder
- T1685 Disable or Modify Tools
- T1005 Data from Local System
- T1059.001 PowerShell
- T1120 Peripheral Device Discovery
- T1195.002 Compromise Software Supply Chain

## Sources

- [PCRisk: ZETARINK Ransomware Removal Guide](https://www.pcrisk.com/removal-guides/34942-zetarink-ransomware)
- [VirusTotal Analysis — ZETARINK SHA256 904cee06...](https://www.virustotal.com/gui/file/904cee06bbc6093213e8653b120b2b72701bac7e8dbfbdd69bfb3aed9b6a7298)
- [Garble — Go Build Obfuscation Tool (GitHub)](https://github.com/burrowers/garble)
- [MITRE ATT&CK — Data Encrypted for Impact (T1486)](https://attack.mitre.org/techniques/T1486/)
- [ID Ransomware — Ransomware Identification Service](https://id-ransomware.malwarehunterteam.com/)
- [No More Ransom Project — Free Decryption Tools](https://www.nomoreransom.org/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0086
