Draft:CompiledCrypt
Submission declined on 20 September 2026 by Accesscrawl (talk).
Where to get help
How to improve a draft
You can also browse Wikipedia:Featured articles and Wikipedia:Good articles to find examples of Wikipedia's best writing on topics similar to your proposed article. Improving your odds of a speedy review To improve your odds of a faster review, tag your draft with relevant WikiProject tags using the button below. This will let reviewers know a new draft has been submitted in their area of interest. For instance, if you wrote about a female astronomer, you would want to add the Biography, Astronomy, and Women scientists tags. Editor resources
|
This draft's references do not show that the subject meets Wikipedia's criteria for inclusion. The draft requires multiple published secondary sources that:
Declined by Giuliotf 7 days ago.
|
Comment: Not notable. Accesscrawl (talk) 11:32, 20 September 2026 (UTC)
Comment: notability has not been shown yet, subject needs to be shown to have receive significant coverage in multiple independent reliable sources Giulio 13:45, 18 September 2026 (UTC)
CompiledCrypt
[edit]CompiledCrypt is a provisional designation for a Windows ransomware program identified in multiple malware samples. The program targets files in common user directories and encrypts their contents using the Advanced Encryption Standard (AES) in Galois/Counter Mode (GCM).
Behavior
[edit]CompiledCrypt targets files located in the user's Desktop, Documents, and Downloads directories. The analyzed program reads the files and combines their contents into a single data buffer before encrypting the resulting data.
The encrypted data is saved as compiled.enc. A README.txt file is also created containing a ransom demand.
After processing a directory, the program deletes the original regular files while leaving the encrypted output and ransom note. First observed on September 13, 2026, CompiledCrypt has been confirmed on five computers, while additional malware samples associated with the program continue to be identified.[1]
Damage
[edit]CompiledCrypt can result in the loss of files stored on an affected computer. The analyzed samples encrypt files and subsequently delete the original files. Because the analyzed implementation does not appear to preserve or transmit the encryption keys, recovery of affected files may not be possible using the program itself.
Five computers have been confirmed as having executed a CompiledCrypt sample. At least three reported incidents involved ransom demands of US$100 worth of Bitcoin.
Encryption
[edit]The analyzed implementation uses AES-256-GCM encryption. A randomly generated encryption key and initialization vector are created during execution.
The implementation also generates a GCM authentication tag. In the analyzed sample, however, the encryption key and authentication tag are not stored with the encrypted data or otherwise made available for recovery.
Persistence
[edit]The program copies its executable into the Windows Startup folder. This causes the executable to be launched when the affected user logs into Windows.
Naming
[edit]"CompiledCrypt" is a provisional research designation referring to the program's use of a file named compiled.enc and its aggregation and encryption of files.[2]
References
[edit]- ↑ "MalwareBazaar | Checking your browser". bazaar.abuse.ch. Retrieved 2026-09-18.
- ↑ "MalwareBazaar | Checking your browser". bazaar.abuse.ch. Retrieved 2026-09-18.


- provide significant coverage: discuss the subject in detail, not just brief mentions or routine announcements;
- are reliable: from reputable outlets with editorial oversight;
- are independent: not connected to the subject, such as interviews, press releases, the subject's own website, or sponsored content.
Please add references that meet all three of these criteria. If none exist, the subject is not yet suitable for Wikipedia.