DarkBit Ransomware
Summary
During the encryption process, DarkBit alters the filenames of the affected files by renaming them with a random character string followed by the .Darkbit extension. Once the encryption process is completed, DarkBit generates a ransom note titled RECOVERY_DARKBIT.txt and places it on the infected systems desktop. DarkBits ransom note begins with a political or geopolitical message, implying that the ransomware targets large entities, such as companies, rather than home users. The ransom note dropped by the DarkBit Ransomware reads: Dear Colleagues, We’re sorry to inform you that we’ve had to hack Technion network completely and transfer “all” data to our secure servers. They should pay for occupation, war crimes against humanity, killing the people (not only Palestinians’ bodies, but also Israelis’ souls) and destroying the future and all dreams we had.