GoodWill Extortionist는 피해자에게 선행을 강요합니다.

CloudSek specialists talked about a strange GoodWill ransomware that does not demand money from the victims, 하지만 forces them do good deeds in exchange for decrypting files.

예를 들면, ransomware operators are told to distribute clothes to the homeless or pay medical bills to those who need urgent medical care but cannot afford it.

Let me remind you that we wrote about 싸구려의 모습 다크크리스탈 RAT 맬웨어 우려 전문가, 그리고 그것도 Microsoft Warns of Increased XorDdos Malware Activity.

연구원에 따르면, 친선 is predominantly distributed in India and, apparently, was created in the same country. It is likely that the ransomware is someone’s experiment, since so far, the experts have not been able to detect a single GoodWill victim.

This malware was first noticed in March 2022. It is known that GoodWill is written in .NET and seems to be built on the basis of the open-source malware HiddenTear. After infecting the system, it sits idle for 722.45 seconds to confuse dynamic analysis and also uses the AES_Encrypt function to encrypt using AES.

After infection, GoodWill encrypts all documents, photos, videos, 데이터베이스, and other important files and leaves a note asking victims to do three good deeds to get the key to decrypt the data. 그래서, malware operators require:

  1. donate new clothes to the homeless, record it on video and post it on social networks;
  2. take at least five children from disadvantaged families to Dominos, Pizza Hut 또는 KFC and feed them, take photos and videos of the process and post them on social networks;
  3. provide financial assistance to those who need urgent medical care but cannot afford it, record the entire conversation and share the audio recording with GoodWill operators.

굿윌 랜섬웨어
굿윌 랜섬웨어
굿윌 랜섬웨어

After completing all these actions, the victim should also write another post on social networks, talking about “turning into a kind person after becoming a victim of the GoodWill ransomware.”

보기에, after that, the ransomware operators check all media files and messages sent by the victim on social networks, and if the conditions are met, they provide a data decryption kit, which includes the decryptor itself, a file with passwords and a video tutorial on how to recover all important data.

헬가 스미스

저는 항상 컴퓨터 과학에 관심이있었습니다, 특히 데이터 보안 및 테마, 요즘은 "데이터 과학", 10 대 초반부터. 편집장으로 바이러스 제거 팀에 오기 전, 저는 여러 회사에서 사이버 보안 전문가로 일했습니다., 아마존 계약자 중 한 명 포함. 또 다른 경험: 나는 Arden과 Reading 대학에서 가르치고 있습니다..

회신을 남겨주

이 사이트는 스팸을 줄이기 위해 Akismet 플러그를 사용. 귀하의 코멘트 데이터가 처리되는 방법 알아보기.

맨 위로 버튼