This article was originally published by 8btc and written by Vincent He.
A ransomware virus named Ryuk has spread to China, asking the users of infected devices for a hefty bitcoin ransom.
Tencent Security reported on July 17, 2019, that it has monitored Ryuk and found that it encrypts data on an infected device and demands a ransom in bitcoin. The ransom is generally very high and has recently reached 11 BTC.
The virus disables victims’ systems with sophisticated ransomware, mainly through botnets. First found in North America, it uses RSA and AES encryption algorithms to encrypt victims’ files. The campaign appears highly targeted, with government and enterprise institutions as preferred victims.
Ryuk originated in the Hermes date code family, and the earliest signs of its activity can be traced back to August 2018. It makes use of most of the Hermes code, has the same white list filtering mechanism as a Hermes virus and it also uses Hermes strings, even for the unique infection marker of files.
The sample found in China releases and runs different blackmail modules, which will help the virus implement subsequent injection and further improve the efficiency of its operation. As part of the most recent attacks, a dropper containing both the 32-bit and 64-bit modules of the ransomware was used. When run, Ryuk checks if it was executed with a specific argument and then kills more than 40 processes and over 180 services belonging to antivirus, database, backup and document editing software.
The blackmail letter left by Ryuk is very simple, with only two blackmail contact mailboxes and blackmail virus names. It does not take long after being answered that the attacker requests a BTC ransom.
Almost all of the observed Ryuk ransomware samples, the security researchers say, were provided with a unique wallet. Shortly after a recent victim paid the ransom, the attackers divided the funds and transmitted them through multiple accounts.
The ransomware also remains on the infected machines and attempts to encrypt network resources in addition to local drives. It also destroys its encryption key and deletes shadow copies and various backup files from the disk to prevent users from recovering files.Earlier this month, Tencent Security reported another Trojan virus called Burimi that has hacked over 33 million email accounts demanding a bitcoin ransom.
The post The Ryuk Virus Is Spreading Through China, Asking 11 BTC Ransoms appeared first on Bitcoin Magazine.
2020 was unforgettable, especially for Bitcoin. To help memorialize this year for our readers, we asked our network of contributors to reflect on Bitcoin’s price action, technological development, community growth and more in 2020, and to reflect on what all of this might mean for 2021. These writers responded with a collection of thoughtful and…
Today’s low interest rate climate is one that further reduces the opportunity cost of holding base, fiat money — a fallacy fixed by Bitcoin.“After the U.S. experience during the Great Depression, and after inflation and rising interest rates in the 1970s and disinflation and falling interest rates in the 1980s, I thought the fallacy of…
Rather than trying to convince people that they want bitcoin, investors are looking for products that use Bitcoin to meet people where they are.This is a transcribed excerpt of the “Bitcoin Magazine Podcast,” hosted by P and Q. In this episode, they are joined by Alyse Killeen to talk about what is happening in the…
Another digital asset platform has received approval to do business in New York. Bitstamp, one of the largest crypto exchange platforms in Europe, has been granted a virtual currency license from the New York State Department of Financial Services (NYSDFS). The exchange became the 19th firm approved to offer crypto-based services in the world's financial…
Bitcoin community leaders can help educate others about the values of bitcoin simply through a localized onboarding process.This is an opinion editorial by Doug, founder of Bitramp and a proponent of local bitcoin on-ramps.The path most traveled in exchanging fiat for access to Bitcoin involves utilizing the service of exchanges, as they are the most…
It is now up to the governor of Wyoming to put the final stamp of approval on the landmark bill.The U.S. state of Wyoming has passed a bill that protects its citizens from having to disclose their private keys, with a singular exception. Having now been approved by the state Senate and House of Representatives,…
The BoE has become the first major central bank to raise interest rates since the pandemic by hiking its basic rates to 0.25%.The Bank of England has become the world’s first major central bank to raise interest rates since last year when the pandemic pushed all large economies to employ accommodative monetary policies.Bitcoin is trading…
Blockchain firm Bitfury will develop a bitcoin mining center in Paraguay. The new mining operation is in partnership with Seoul-based research and development firm Commons Foundation. The collaboration is backed by the government of Paraguay, whose goal is to make the South American country a cryptocurrency mining hub. The new center, which is a part…
David Marcus, former lead of Facebook Messenger, announced the creation of Lightspark, a Lightning Network infrastructure company.David Marcus, ex-Meta executive for Facebook Messenger, has announced the creation of his new company, Lightspark.Lightspark will focus on building, exploring and creating on the Bitcoin Lightning Network. Marcus notes his passionate belief that led to this decision was…