Malware News New Enigma Ransomware Targets Only Russian Users

A

Alkajak

Thread author
AVG security researcher Jakub Kroustek has discovered a new ransomware that's targeting only Russian-speaking users named Enigma, which, under certain conditions, can allow users to recover some of their files using Shadow Volume Copies.

Analyzed by researchers from MalwareHunterTeam and Bleeping Computer, the ransomware encrypts files with the now de-facto AES-RSA dual encryption model, and then stores the encryption key on the computer's Desktop in the form of a file named ENIGMA_[NUMBER].RSA.

If users want the decryption key, they'll have to pay crooks 0.4291 Bitcoin, which is about $200. As with other ransomware families, payment must be made by accessing a browser on the Tor network, via the Tor Browser. On the payment site they'll be asked to upload the file mentioned above.

Enigma ransomware uses HTML files to deliver its payload.

[...]

Full Article: We're Currently Safe: New Enigma Ransomware Targets Only Russian Users
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top