HelloXD Ransomware

General News

Summary

The HelloXD Ransomware is a potent malware threat, with cybercriminals using it in attacks against both Windows and Linux systems. HelloXD generates a specific ID for each infected system that victims are supposed to send to the attackers to receive the correct decryption keys. In practice, this means that the data of the breached devices is exfiltrated to a remote server before the encryption routine is engaged. The hackers could be moving away from this behavior - some of the more recent ransom notes dropped by HelloXD contain a link to an as-of-yet inactive website hosted on the Onion network. One of the more peculiar discoveries made by the Unit 42 researchers is that one HelloXD sample dropped a backdoor threat on the infected device.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M