Cyware Daily Threat Intelligence December 04, 2017

Top Malware Reported in the Last 24 Hours
Shadow BTCware
Recently, a new variant of the BTCWare ransomware has been discovered recently. This new variant attaches the [email]-id-id.shadow extension to encrypted files. The BTCWare ransomware family targets victims by hacking into poorly protected remote desktop services and manually installing the ransomware.

Want Money ransomware
A crypto ransomware dubbed Want Money encrypts user files and extorts money to decrypt them. Once triggered, the malware encrypts the user files using AES-256 encryption. It restricts the chance for the users to restore files by deleting all the shadow copies or restore points.

Halloware ransomware
A malware author by the name of Luc1F3R is peddling a new ransomware strain called Halloware for the lowly price of $40. The ransomware encrypts files using a hardcoded AES-256 key and prepends the "(Lucifer)" string to encrypted files. As the ransomware uses a hardcoded AES key and does not save any information on a remote server, recovering encrypted files is not possible.



Tags


    • Share this blog:
    To enhance your experience on our website, we use cookies to help us understand how you interact with our website. By continuing navigating through Cyware’s website and its products, you are accepting the placement and use of cookies. You can also choose to disable your web browser’s ability to accept cookies and how they are set. For more information, please see our Privacy Policy.