Payload ransomware uses ChaCha20 and Curve25519 to lock Windows files
VPN Central [Unofficial]
May 28, 2026
Payload ransomware is an emerging Windows-focused threat that uses ChaCha20 encryption and Curve25519 key exchange to lock victim files. Security researchers say the malware appends the .payload extension, drops a RECOVER_payload.txt ransom note, and uses anti-forensics features to make recovery harder. The ransomware appeared in February 2026 and quickly drew attention because of its technical […]
The post Payload ransomware uses ChaCha20 and Curve25519 to lock Windows files appeared first on VPN Central.
Discussion in the ATmosphere