Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!



   1953

Kadavro Vector Ransomware v3 RaaS | Aes256-GCM (ChaCha20 combination) | E2ND ID

by angelbanker - 27 April, 2024 - 05:49 PM
This post is by a banned member (angelbanker) - Unhide
130
Posts
17
Threads
(This post was last modified: 06 December, 2024 - 11:31 PM by angelbanker. Edited 6 times in total.)
5/7/2024 - The project has been resumed and is open for adverts and serious inquiries.
[Image: maxresdefault-1.jpg]
IVAN - Infiltrate and Vanquish American Networks
Kadavro Vector Ransomware v3 - an advanced ransomware program.

Crafted by seasoned and daring developers who know their craft.
Brief overview of features:
● File encryption using Aes256-GCM algorithm.
● Encryption of decryption key using Block Chaining Cipher combined with curve25519. Older algorithms vulnerable to key hashing collisions have been removed.
● Anti-CIS, Kadavro will not execute in the post-Soviet space, specifically in the following countries:
  - Belarus
  - Kazakhstan
  - Uzbekistan
  - Azerbaijan
  - Turkmenistan
  - Georgia
  - Armenia
  - Moldova
  - Kyrgyzstan
  - Tajikistan
  - Russia
● UAC bypass (custom powershell script (FUD)).
Payload:
● 3 .NET forms, primary form appears after encrypting all files.
● List of encrypted files.
● Generating QR code based on specified Monero address.
● Countdown timer until all files are deleted.
● Every 20 seconds, the sum specified in the builder increases by $10.
● 2nd form contains decryption labels | Basic decryption of all files | Decrypting one file for locker legitimacy.
● 3rd form with bug bounty and Telegram chat for sending bugs with contacts.
● 11 languages of Western countries and beyond.
● Custom HTML file using JavaScript and CSS.

Builder:
● Flexible settings.
● Option to specify Monero address (only), contact details, hours, minutes, attempts on incorrect key input, extension, dollar amount.
● Log retrieval: via Telegram bot (token and chat ID) or any hosting, .onion addresses also supported. PHP file for logs is provided with the builder.
● Two encryption modes: encrypting all files | encrypting with specified extension.
● Anti-virtual environments.
● Anti-emulators.
● Anti-debugger.
● Startup task manager.
● Detection and anti-run in sandbox.
● Anyrun.
● Removal of backups and restore points.
● Option to set properties and icons.
● Automatic file obfuscation.
We are not a public hacking group, we operate privately and do not accept people without experience in ransomware distribution.
1) Experience with ransomware.
2) Experience in distribution.
We are not chasing money, we are chasing reputation, giving you the opportunity to earn.
Why work with us?
There was much talk about the first version of Kadavro in popular news publications. As of 2023, there were no decrypters for Kadavro. Even if there were, they were not functional.
We consistently operate actively, answering all your questions.
We allow encryption of whatever you want, individuals and corporate entities, companies of any income level.
We have never deceived and do not intend to, ready for long-term cooperation.
Do not write to us that you want to try hard or try to work with ransomware.

If we notice that you are inactive within 7 days, without notifications of why you are inactive, you will be blocked, and your builder license will be permanently disabled without the possibility of recovery.

We provide Kadavro ransomware for testing only to moderators/staff of this forum. Do not write to us if you do not have money for rent or if you are not ready.

For all inquiries, write in PM on the forum or under this thread.

Prices:
2 months rental - $380
9 months rental - $1710

Contacts for rent:
My qTox ID - 0DF8A8515581B7BE24D2FC1F107AD38E20E6F26F6DF83E6C30AB49FF4707BD5720A0F4A38AB5
[Image: MrMonero.png]

My Session ID - 05eca1eae9cd4c27373b635def91514bd682cddd3bcc26d1c857bbcff3c7d28624

Second developer n1k7:
Session ID - 052b804fe69983cef6346fbbcc14053d418b967faba357eebaa9166f203bb36266

Telegram - none and will not be, do not feed scammers and other scoundrels.
This post is by a banned member (0x314) - Unhide
0x314  
Supreme
938
Posts
262
Threads
2 Years of service
#2
glws [Image: wave2.gif] [Image: kekg2.gif]

[Image: 9lRmxuD.gif]
This post is by a banned member (cragster) - Unhide
This post is by a banned member (angelbanker) - Unhide
130
Posts
17
Threads
#4
(This post was last modified: 08 May, 2024 - 03:28 AM by angelbanker. Edited 2 times in total.)
The project is closed indefinitely.
Please check with your contacts:

My Session ID: 05eca1eae9cd4c27373b635def91514bd682cddd3bcc26d1c857bbcff3c7d28624
My qTox ID: 0DF8A8515581B7BE24D2FC1F107AD38E20E6F26F6DF83E6C30AB49FF4707BD5720A0F4A38AB5

n1k7 Session ID: 052b804fe69983cef6346fbbcc14053d418b967faba357eebaa9166f203bb36266 (n1k7)
This post is by a banned member (n1k7) - Unhide
n1k7  
Supreme
245
Posts
4
Threads
#5
This is a BUMP for my friend here. ++
AFFORDABLE BUT POWERFUL AND LOW DETECTION CRYPT SERVICE, 0/26 on AVCHECK.NET GUARANTEE:
https://cracked.io/Thread-EchoCrypt-Prot...id37984886

 
Telegramhttps://t.me/n1k7l


This post is by a banned member (angelbanker) - Unhide
130
Posts
17
Threads
Bumped #6
This is a bump
This post is by a banned member (n1k7) - Unhide
n1k7  
Supreme
245
Posts
4
Threads
#7
(This post was last modified: 08 May, 2024 - 03:51 AM by n1k7. Edited 5 times in total.)
New Update

[+] Added page with Bug Bounty and personal support in Telegram chat.
[Image: Screenshot-10.png]
[Image: Shooter-Screenshot-553-30-04-24.png]
[+] Added option to disable subsequent elements/removal/stop of SmartScreen and spyware notification:
• GroupPolicyRefresh\TimeDC
• GroupPolicyRefresh\TimeOffsetDC
• GroupPolicyRefresh\Time
• GroupPolicyRefresh\TimeOffset
• EnableSmartScreen
• del.ShellSmartScreenLevel
• DisableAntiSpyware
• DisableRoutinelyTakingAction
• DisableRealtimeMonitoring
• DisableBehaviorMonitoring
• SubmitSamplesConsent
• SpynetReporting
• EnableFirewall


Contacts for purchasing:

Contacts for rent:

AngelBanker qTox ID - 0DF8A8515581B7BE24D2FC1F107AD38E20E6F26F6DF83E6C30AB49FF4707BD5720A0F4A38AB5
[Image: MrMonero.png]

AngelBanker Session ID - 05eca1eae9cd4c27373b635def91514bd682cddd3bcc26d1c857bbcff3c7d28624

2nd Developer N1k7:
Session ID - 052b804fe69983cef6346fbbcc14053d418b967faba357eebaa9166f203bb36266

Telegram - none and will not be, do not feed scammers and other scoundrels.
AFFORDABLE BUT POWERFUL AND LOW DETECTION CRYPT SERVICE, 0/26 on AVCHECK.NET GUARANTEE:
https://cracked.io/Thread-EchoCrypt-Prot...id37984886

 
Telegramhttps://t.me/n1k7l


This post is by a banned member (angelbanker) - Unhide
130
Posts
17
Threads
Bumped #8
This is a bump

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 2 Guest(s)