Incidents

Malicious encryption programs

Recently we’ve noticed several versions of one malicious program spreading. The program encrypts users files. In the last week we’ve had more requests from users to decrypt encrypted files.

An de-encryption routine has been added to antivirus databases for encrypted files. The encrypted files are detected as Virus.Win32.Gpcode.

The string PGPcoder is in the beginning of encrypted versions of files.

On PCs with encrypted files users may find files which contain warnings in Russian. In translation, the warnings say:

The contents of some of your files have been encoded using encoder ver 1.2. For decoding contact the following address: xcv789@mail.ru

Some of your files have been encoded using CRZ. For decoding contact: bnm7814@yahoo.com or ztc567@mail.ru]

Malicious encryption programs

Your email address will not be published. Required fields are marked *

 

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Reports

Crypto wasted: BlueNoroff’s ghost mirage of funding and jobs

Kaspersky GReAT experts dive deep into the BlueNoroff APT’s GhostCall and GhostHire campaigns. Extensive research detailing multiple malware chains targeting macOS, including a stealer suite, fake Zoom and Microsoft Teams clients and ChatGPT-enhanced images.

Mem3nt0 mori – The Hacking Team is back!

Kaspersky researchers discovered previously unidentified commercial Dante spyware developed by Memento Labs (formerly Hacking Team) and linked it to the ForumTroll APT attacks.

Mysterious Elephant: a growing threat

Kaspersky GReAT experts describe the latest Mysterious Elephant APT activity. The threat actor exfiltrates data related to WhatsApp and employs tools such as BabShell and MemLoader HidenDesk.