HelloXD Ransomware
Summary
The HelloXD Ransomware is a potent malware threat, with cybercriminals using it in attacks against both Windows and Linux systems. HelloXD generates a specific ID for each infected system that victims are supposed to send to the attackers to receive the correct decryption keys. In practice, this means that the data of the breached devices is exfiltrated to a remote server before the encryption routine is engaged. The hackers could be moving away from this behavior - some of the more recent ransom notes dropped by HelloXD contain a link to an as-of-yet inactive website hosted on the Onion network. One of the more peculiar discoveries made by the Unit 42 researchers is that one HelloXD sample dropped a backdoor threat on the infected device.
Classifications
industries
Entertainment
applications
Customer Service & Support
AskAI Classifications
Labels
Cybersecurity Software
Anti-Malware Software
SaaS Security
Linked Companies
EnigmaSoft
$1M to $5M