New ransomware appears attacking Windows operating system
This malware has appeared since March and has had 16 victims, mainly in the US, operating in the real estate, education, healthcare and manufacturing sectors.
Eldorado is a new and completely independent ransomware. It uses the Go language for cross-platform attacks. This malware encrypts files using the ChaCha20 algorithm and generates a unique 32-byte key and a 12-byte nonce for each locked file. The keys are then encrypted using RSA-OAEP.
After encryption, the file will be renamed ".00000001" and a ransom note named 'HOW_RETURN_YOUR_DATA.TXT' will be added to the Documents and Desktop folders.
In particular, Eldorado has the ability to customize to attack specific directories. This malicious code is even installed by default in self-delete mode to avoid being detected by users and analyzed by incident response teams.
To prevent ransomware in general and Eldorado in particular, experts recommend that users urgently deploy the following defensive measures:
- Implement a multi-factor authentication (MFA) solution and credential-based access.
- Back up data regularly to minimize damage and avoid data loss.
- Regularly update security patches to fix vulnerabilities.
- Detect and prevent intrusions quickly using AI-based analytics and advanced malware detection solutions.
- Quickly identify and respond to ransomware indicators using Endpoint Detection and Response (EDR).
- Train employees to recognize and report cybersecurity threats.
- Conduct regular and periodic technical audits or security assessments.
- Refuse to pay the ransom because data recovery is difficult and could lead to more attacks.
You should read it
- Research: The golden time to prevent malicious code after the system is compromised
- Strange ransomware detection only attacks the rich
- How to prevent malicious blackmail JPG code via Facebook Messenger
- Is Ransomware Annabelle scary with Annabelle movies?
- How to handle the emergency WannaCry malicious code from the National Information Security Department
- Detection of a new ransomware strain targeting the Windows search engine
- Ryuk Ransomware has added 'selective' encryption capabilities.
- Warning: The new Facebook virus, a malicious code that is spreading rapidly through Messenger
May be interested
- Favorite free features on Canvacanva offers many graphic design tools and features, but many are only available to canva pro users. however, you can access many great tools from a free canva account.
- The Hubble Telescope sent back to Earth its first photo after changing its operating methodthe hubble space telescope recently encountered some operating troubles, leading to scientists being forced to change the way it operates.
- This is the reason many people refuse to use Meta AI on any Meta platform!integrating meta's ai features across the company's platforms appears to be the final step in making ai accessible to billions of people worldwide.
- Extremely detailed brain map shows the activity of neurons that encode languageby 'eavesdropping' on brain activity, scientists have created the highest resolution map of the neurons that encode the meaning of various words.
- Why should all social media platforms implement Community Notes?the community notes feature is one of the few widely accepted x changes that elon musk has supported. but moderation still has its flaws, so can it really show the way to a better social media landscape?
- Instructions for creating mouse pointer highlights on Windowsthe cursor highlighter application will create a highlight effect for the mouse cursor on your computer, highlighting the cursor, making it easier for you and your viewers to follow during presentations, tutorials and live streams.