A ransomware known as ChastityLockwas used by hackers to target owners of the adult game Qiui Cellmate.

The source code of the malware has now been published so that it can be further studied by experts.
The game is a "chastity belt" known as Qiui Cellmate, which is aimed at men and controlled via Bluetooth. As security researchers found, the game had a vulnerability that could allow a hacker remote control.
The Qiui Cellmante is a sex toy that also has a companion app, which allows another person to lock and unlock the device via Bluetooth.
But in October 2020, researchers from Pen Test Partners discovered a serious vulnerability in the game, which could allow an unauthorized person to remotely control the device.
According to the researchers, making a request to any API endpoint does not require authentication, and using a six-digit “friend code” would return “a huge amount of information about that user,” such as location, phone number, plain text password, and more.
A hacker managed to take control of the Qiui Cellmate app and asked its victims to pay 0.02 bitcoin, about $270 (222 euros), when the ransomware attack.

The source code for the ChastityLock ransomware, published by the founder of VXUnderground, includes code that communicates with Qiui API endpoints to retrieve victims' information and send messages through the app.
Many users began to complain that they could no longer control their devices, while some fell victim to the attacker more than once.
After the hacker managed to take control of the game, he would communicate with his victims and even taunt them, saying that he used magic to lock their devices.
Some users were concerned that the only way to remove the Cellmate device was to cut it off, as there was no manual alternative.
However, as its lock is made of hardened steel, cutting it requires special tools that can be dangerous for the sensitive area.
Fortunately, there were some unlocking options. Owners could contact support and request that they unlock and reset the Cellmate. They could also use a screwdriver to unlock the device manually. Finally, they could void the product's warranty.
The company has addressed the issues that led to this entire issue, so the latest version of the app should be safe to use.
