랜섬웨어는 Roblox Game Pass 스토어에서 암호 해독기를 판매합니다.

Chaos builder

The MalwareHunterTeam has discovered a new ransomware sample built with the Chaos builder. 악성코드, 워너프렌미라고 불렀어, is remarkable because it offers to buy a Roblox game pass for the currency accepted on this online platform as a ransom.

The Roblox platform is very popular with children, who get the opportunity to create their games and monetize them by selling subscriptions (Game Pass). Such a pass, which gives the player special perks and benefits, can only be purchased with an in-game currency called Robux.

The WannaFriendMe ransom note says that the decryptor can be purchased by purchasing a Game Pass at the Roblox address provided. The purchase is possible only if you have an account on the platform, the issue price is 1700 Robux.

Ryuk Decrypter

이후, you should take a screenshot confirming the fulfillment of the condition, and send it along with the username to @icloud.com. Having visited the Roblox page indicated by the link, the BleepingComputer expert discovered that the decryptor for the pseudo-Ryuk has fallen in price and someone iRazormind is selling it.

BGZQ 바이러스 (.bgzq 파일) 랜섬웨어

Bgzq 랜섬웨어

Bgzq 바이러스는 STOP/Djvu 랜섬웨어 그룹에 속하며 Windows 컴퓨터를 표적으로 삼습니다.. 이 컴퓨터의 파일을 암호화하여 작동합니다., 이를 사용하여 파일로 변경 “.Bgzq” 확대,…

BGJS 바이러스 (.bgjs 파일) 랜섬웨어

Bgjs 랜섬웨어

Bgjs 바이러스는 STOP/Djvu 랜섬웨어 그룹에 속하며 Windows 컴퓨터를 표적으로 삼습니다.. 이 컴퓨터의 파일을 암호화하여 작동합니다., 이를 사용하여 파일로 변경 “.bgjs” 확대,…

The newly minted ransomware also tries to impersonate its once-formidable brother Ryuk (appends the .ryuk extension to files), but it actually borrows the Chaos code. A malware builder based on Chaos has been on the underground market for a year now, and inexperienced virus writers are willing to use it to create custom variants, such as Onyx. Last year, one such iteration surfaced in attacks on the Minecraft gaming community.

Chaos infection is bad because paying the ransom does not guarantee the recovery of all data. This malware cannot encrypt files larger than 2 MB, it overwrites them so that it is no longer possible to return the contents. 결론적으로, it is worth noting that the idea of ​​using Roblox for extortion is not new: last year it was implemented by the operators of malware based on HiddenTear.

코멘트를 남겨주세요