FireCrypt - The Ransomware with DDoS Component
A new ransomware-as-a-service, called BleedGreen, allows users to run and perform the FireCrypt ransomware which also attempts a DDoS attack. BleedGreen’s creators have locked the ransom value and the contact email details.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
A new ransomware-as-a-service, called BleedGreen, allows users to run and perform the FireCrypt ransomware which also attempts a DDoS attack. BleedGreen’s creators have locked the ransom value and the contact email details.
Affected platforms
The following platforms are known to be affected:
Threat details
The ransomware is deployed via spam emails and is activated when the user launches the EXE. file attachment. FireCrypt adds the extension“.firecrypt” to the encrypted files, targeting twenty file extensions including documents, images and videos.
Once the encryption process has completed the ransom note is deployed and FireCrypt attempts to launch a DDoS attack against Pakistan’s Telecommunication Authority from the user's device. At the time of publication it’s not known why they are the target of the attack but there hasn't been a successful DDoS attack from FireCrypt.
Remediation steps
| Type | Step |
|---|---|
|
If a computer on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
The only guaranteed way to recover from a ransomware infection is to restore all affected files from their most recent backup. |
Last edited: 11 January 2022 3:02 pm