Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

Detecting a New Ransomware Strain, Not Asking for Data

Explore detecting a new ransomware strain, not asking for data with clear explanations, useful context, practical examples, and actionable tips that are.

Table of Contents

This guide provides a clear, practical overview of detecting a new ransomware strain, not asking for data, with useful context, important details, and straightforward takeaways for everyday readers.

More specifically, security researcher from MalwareHunterTeam just found a decryptor developed for 'Hog ransomware', which requires victims to join the Discord server if they want their files to be resolved. code.

The encryptor of the malicious code was later discovered. When executed, it checks to see if a particular Discord server exists and, if so, will start encrypting the victim's file.

When successfully encrypting a victim's file, the malicious code appends the .hog extension to the file extension as shown below, and automatically extracts the decoder component.

Detecting a New Ransomware Strain, Not Asking for Data

After Hog has encrypted the target device, it will immediately launch the DECRYPT-MY-FILES.exe decoder from the Windows Startup folder.

Detecting a New Ransomware Strain, Not Asking for Data

This decoder will explain the victim in detail what happened to them, and then prompt the victim to enter the Discord user token created specifically for them.

Detecting a New Ransomware Strain, Not Asking for Data

If you don't already know, Discord is a voice and text chat system that allows you to communicate with others. Anyone can create a discussion host whatever they want. You can find people to talk to about Valkyrie and form teams at most times of the day. Learn more about Discord in THIS article.

The Discord token allows the ransomware to authenticate against the Discord APIs as users and check if they join their server, as shown by the source code below.

Detecting a New Ransomware Strain, Not Asking for Data

If the victim joined the server or the server doesn't exist, the ransomware decrypts the victim's files using the static key embedded in the ransomware.

While this appears to be a ransomware in development, it does show a tendency for threat actors to start using Discord more often for malicious activities.

Another ransomware named Humble was recently spotted by Trend Micro, using a webhook to post details about the new victims to the hackers' Discord server.

In addition, Discord is often used by threat agents to spread malware or collect stolen data.

In the face of this situation, it is important that administrators and network security tools increase the deployment of Discord traffic monitoring for early detection of threats or unusual behavior.

Key Takeaways

Use the information above as a practical reference for detecting a new ransomware strain, not asking for data. Review each step carefully, confirm any requirements, and choose the option that best fits your situation.

FAQ

What does this guide explain about Detecting a New Ransomware Strain, Not Asking for Data?

It explains the main concepts, practical considerations, and useful steps related to detecting a new ransomware strain, not asking for data without requiring advanced knowledge.

Who can benefit from learning about Detecting a New Ransomware Strain, Not Asking for Data?

This information is useful for readers who want a clear overview, practical guidance, and reliable steps related to detecting a new ransomware strain, not asking for data.

What should I check before applying this information?

Review the requirements, confirm that your device, software, or situation matches the instructions, and back up important data before making major changes.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.