New 0mega ransomware targets businesses in double-extortion attacks

Gandalf_The_Grey

Level 76
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,600
A new ransomware operation named ‘0mega’ targets organizations worldwide in double-extortion attacks and demands millions of dollars in ransoms.

0mega (spelled with a zero) is a new ransomware operation launched in May 2022 and has attacked numerous victims since then.

A ransomware sample for the 0mega operation hasn’t yet been found, therefore there’s not much information on how files are encrypted.

However, we do know that the ransomware appends the .0mega extension to the encrypted file’s names and creates ransom notes named DECRYPT-FILES.txt.

These ransom notes are customized per victim, usually containing the company name and describing the different types of data stolen in attacks. In addition, some notes include threats on how the 0mega gang will disclose the attack to business partners and trade associations if a ransom is not paid.

These ransom notes include a link to a Tor payment negotiation site with a "support" chat that victims can use to contact the ransomware gang.

To log in to this site, victims must upload their ransom notes that include a unique Base64-encoded blob used by the site to identify the victim.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top