
Post-quantum malware refers to the hypothetical future threat of malware leveraging quantum computing to break current cryptographic protections (RSA, ECC). While sufficiently powerful quantum computers don’t yet exist, adversaries are conducting “harvest now, decrypt later” (HNDL) campaigns — collecting encrypted data today for decryption once quantum computers mature.
| Algorithm | Classical Security | Quantum (Shor’s) |
|---|
| RSA-2048 | ~112 bits | Broken |
| RSA-3072 | ~128 bits | Broken |
| ECC P-256 | ~128 bits | Broken |
| ECC P-384 | ~192 bits | Broken |
| AES-256 | 256 bits | 128 bits (Grover’s) |
| SHA-256 | 256 bits | 128 bits (Grover’s) |
| Phase | Description |
|---|
| 1. Harvest Now | Collect encrypted traffic, TLS sessions, VPN traffic, encrypted files, backups |
| 2. Store | Long-term cold storage; data retains value for decades |
| 3. Wait | Wait for Cryptographically Relevant Quantum Computer (CRQC) |
| 4. Decrypt Later | Run Shor’s algorithm on CRQC to break RSA/ECC keys |
| 5. Exploit | Decrypt harvested data; forge signatures; impersonate identities |
| Data Type | Sensitivity Lifetime | Risk |
|---|
| State secrets | 25-50+ years | Critical |
| IP / Trade secrets | 10-30 years | Critical |
| PII / Medical | 10-20+ years | High |
| Financial records | 7-10 years | High |
| TLS session keys | Ephemeral | Low (PFS helps) |
| Source | CRQC Estimate |
|---|
| NIST | 2030-2040 |
| NSA/CISA | ”Within 10-15 years” |
| Academic | 15-30 years |
| Commercial (IBM, Google) | 2030+ |
| Algorithm | Type | Standardised |
|---|
| CRYSTALS-Kyber | KEM | 2024 (FIPS 203) |
| CRYSTALS-Dilithium | Signature | 2024 (FIPS 204) |
| FALCON | Signature | 2024 (FIPS 205) |
| SPHINCS+ | Signature | 2024 (FIPS 206) |
- ✅ Inventory all crypto — Certificates, VPNs, SSH, TLS, disks, backups
- ✅ Migrate to PQC — Kyber (KEM), Dilithium (sig), hybrid modes
- ✅ Crypto-agility — Design for algorithm swaps without redesign
- ✅ Minimise data lifetime — Don’t store sensitive data for decades
- ✅ Hybrid cryptography — Classical + PQC during transition
- ✅ Monitor NIST PQC — Standards finalised 2024; implement
- ✅ TLS 1.3 + PFS — Ephemeral keys limit HNDL value
| Technique | ID | Relevance |
|---|
| Exfiltration | T1041 | Harvest encrypted data |
| Subvert Trust Controls | T1553 | Forge signatures post-quantum |