Categories: News

In China, a new Ransomware virus Ryuk is Being Distributed

A ransomware virus called Ryuk is distributed in China and requires users of infected devices to pay a large amount in BTC.

Tencent Security examined the Ryuk virus and found that it encrypts data on the infected device and requires a ransom from the BTC. The buyback is usually quite large compared to similar attacks in the past and has recently risen to 11 BTC.

The virus blocks victim systems using a modern hacker program, mainly through bot networks. It was first discovered in North America and uses RSA and AES algorithms to encrypt victims’ files. It seems that the campaign is focused, and its victims are government agencies and private organizations.

Ryuk originated from the Hermes code family, and the earliest signs of its activity can be traced.
until August 2018. It uses most of the Hermes code, has the same whitelist filtering mechanism as the Hermes virus, and also uses the Hermes string sequences even for a unique file infection marker.

The sample found in China releases and launches various modules that will help the virus unfold and further improve its efficiency. In recent attacks, a dropper was used, containing both 32-bit and 64-bit modules of the virus. When Ryuk starts, it checks whether it has been executed with a specific argument, and then interrupts more than 40 processes and more than 180 services related to antivirus, databases, software for backing up and editing documents.

btc ransomware

According to the researchers, almost all of the Ryuk virus samples detected had a unique BTC address. Shortly after the victim pays the ransom, the attackers split the bitcoins and transfer them to several accounts.

The extortionist also remains on infected devices and tries to encrypt network resources in addition to local drives. It also destroys its encryption key, shadow copies and various backup files from disk to prevent users from restoring files.

Recently, New York College Monroe underwent
attack of the ransomware virus – hackers demanded a ransom of 170 BTC. In addition, at the end of last month, the authorities of the American city of Lake City paid
to extortioners a ransom of 42 BTC after the attack of the encryption virus.

Miners Hashrate

Recent Posts

Mining RTX 3070 at NiceHash: Overclocking, tuning, profitability, consumption

Mining on RTX 3070. Overclocking, tuning, profitability, consumption: If you are interested in finding more…

6 months ago

Mining GTX 1660, 1660 Ti, 1660 Super: Overclocking, settings, consumption

Mining with GTX 1660, 1660 Ti, 1660 Super. Overclocking, settings, consumption, profitability, comparisons - If…

6 months ago

Mining RTX 2070 and 2070 Super: Overclocking, profitability, consumption

Mining with RTX 2070 and 2070 Super. Overclocking, profitability, consumption, comparison What the RTX 2070…

6 months ago

Mining with RTX 3060, 3060 Ti. Limitations, overclocking, settings, consumption

Mining with RTX 3060, 3060 Ti. Limitations, overclocking, settings, consumption, profitability, comparison Let's look at…

6 months ago

Alphacool Eisblock Aurora Acryl GPX-A Sapphire – test: 2.8 GHz++ are not an issue

Alphacool Eisblock Aurora Acryl GPX-A (2022) with Sapphire Radeon RX 6950 XT Nitro+ Pure in…

6 months ago

Corporate Crypto Strategies 4.0: Leading with Bitcoin Expertise

In the ever-evolving landscape of business strategy, Bitcoin has emerged as a pivotal asset. With…

6 months ago

This website uses cookies.


Notice: ob_end_flush(): failed to send buffer of zlib output compression (1) in /home/gamefeve/bitcoinminershashrate.com/wp-includes/functions.php on line 5420

Notice: ob_end_flush(): failed to send buffer of zlib output compression (1) in /home/gamefeve/bitcoinminershashrate.com/wp-includes/functions.php on line 5420