Tutu Ransomware
Summary
To impede data recovery efforts, it encrypts these files while concurrently taking measures such as turning off the firewall and eradicating the Shadow Volume Copies. The propagation of Tutu occurs through exploiting vulnerable Remote Desktop Protocol (RDP) services, predominantly utilizing brute force and dictionary-type attacks on systems where account credentials are inadequately managed. Establishing persistence in the infected system is a priority for Tutu, achieved by copying itself to the %LOCALAPPDATA% path and registering with specific Run keys. The ransom note delivered by the Tutu Ransomware communicates a severe threat to victims, claiming that all databases and personal information have been downloaded and encrypted. The main ransom note of the Tutu Ransomware delivers the following message: We downloaded to our servers and encrypted all your databases and personal information!