It's a 16-bit version of Salsa20, which is far less secure. Proof: this project. I have no clue what possessed the author to do this.
Stop hand-rolling crypto, people! Ransomware needs security too. :(
Stop hand-rolling crypto, people! Ransomware needs security too. :(
The author probably wanted to be able to somewhat quickly encrypt/decrypt a full disk on potentially slow hardware.
It would have been smarter to bundle the ransomware with a 32-bit DOS extender so the known-good Salsa implementation could be used unchanged.