Anonymous Ransomware haunts China – Large Spread Infections!

China deemed as a prodigy of technological outbreaks encountered unprecedented number of major cyber threats in last few years. Since the extensive destructive days of WannaCry and NotPeyta last year, ransomware attacks appeared to have dwindled heaving a sigh of relief among security researchers.New Ransomware Attack
A recent discovery of this distinctive cyber attack targeting China got the cyber security back to work. Unlike almost every ransomware malware that seek for ransom payments in Bitcoin, this ransomware virus demands for ransom through one of the country’s most popular payment methods.  WeChat Pay, one of China’s most commonly used digital wallets, owned by Chinese tech giant Tencent, was used by attacker to receive payments.
 Threat Behavior
This anonymous ransomware after infiltrating the system encrypts user’s files using a less secure XOR cipher. However, the ransom note claims to have used a more sophisticated DES encryption algorithm to mislead.
All the files are targeted in the infected system except for files with gif, exe, & tmp extensions.
Users are informed about the encryption via a ransom note that seeks for 110 yuan from the victim to regain access to the files. It asks users to make payment by scanning a WeChat QR code that appears in the pop- window.WeChat QR code
The note threatens users to transfer the declared amount to attacker’s WeChat account within 3 days. Failing to do so may result in the deletion of the decryption key from the remote command and control server, as per the ransom note.
However, the victims should ignore such threats & never agree to pay in any case because their concerns are often disregarded, once the ransom is paid.

Other important characteristics of this unchristened Ransomware

Read More :- Click here

Comments

Popular posts from this blog

How to remove Speedtest-guide.com redirect from your system

The novel DNS protocol helps Mozart Malware evade detection

How to remove ZUpdater.exe Trojan from your system?