{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreihzxgi7qzowktuxb4ihagmv6udaa6hioemai4ln7p7zucaxfvm34e",
"uri": "at://did:plc:6wtxqaikjf62unmnajbfbq5v/app.bsky.feed.post/3mn2me66hglm2"
},
"coverImage": {
"$type": "blob",
"ref": {
"$link": "bafkreibbpiq2cd6yuhn52yajvyt7qh76yfykhmrzgyiy7jhqam6e3yahrq"
},
"mimeType": "image/webp",
"size": 38856
},
"path": "/payload-ransomware-uses-chacha20-and-curve25519-to-lock-windows-files/",
"publishedAt": "2026-05-28T18:22:11.000Z",
"site": "https://vpncentral.com",
"tags": [
"News",
"Payload ransomware uses ChaCha20 and Curve25519 to lock Windows files",
"VPN Central"
],
"textContent": "Payload ransomware is an emerging Windows-focused threat that uses ChaCha20 encryption and Curve25519 key exchange to lock victim files. Security researchers say the malware appends the .payload extension, drops a RECOVER_payload.txt ransom note, and uses anti-forensics features to make recovery harder. The ransomware appeared in February 2026 and quickly drew attention because of its technical […]\n\nThe post Payload ransomware uses ChaCha20 and Curve25519 to lock Windows files appeared first on VPN Central.",
"title": "Payload ransomware uses ChaCha20 and Curve25519 to lock Windows files"
}