Ransomware Roundup: Cryptonite Ransomware

skywatcg-alert-2

  • ransom-4

    TLP-GREEN


FortiGuard Labs has reported on Cryptonite ransomware, which was found to target Microsoft Windows machines by encrypting files and demands a ransom for the file decryption.

Cryptonite is a fully functional ransomware that exists as a Free and Open Source (FOSS) and is programmed in Python.

Additionally, a server must be configured to receive input from a malicious payload running on a victim machine.

The adversary utilizes NGrok to establish a reverse proxy that hides the IP address.

SkyWatchSM Alert Legend

  • small-bell

    Warning

  • active-threat0-lt-green

    Active Threat

  • malware-lt-green

    Malware

  • ransome-lt-green

    Ransomware

  • warning-green

    Phishing

  • file-green

    Network/IOT

Glesec Information Sharing Protocol

GLESEC CYBER SECURITY INCIDENT REPORTS are in compliance with the U.S. Department of Homeland Security (DHS) Traffic-Light Protocol (TLP).

  • TLP-White

    Disclosure is Not Limited.

  • TLP-Green

    Limited Disclosure, Restricted Only to the Community.

  • TLP-Amber

    Limited Disclosure, restricted to the Participant's Organization.

  • TLP-Red

    Not for Disclosure, Restricted/ Classified - Only Shared with US DHS.

Discover Glesec.

Authority. Consistency.

Sign-up today for SkywatchSM Alerts.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.