Sage 2.0 Ransomware
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
The emails often have a missing subject line and no message within the body of text except for a zip file attachment containing malicious macros that download and execute the installer.
The installer stores its executable in the user’s ‘AppData\Roaming’ directory and creates a ‘scheduled task’ to ensure the ransomware runs every time the user logs in to Windows. Any backups taken as Windows Shadow Volume copies are deleted.
The installer execution depends on the user accepting a User Account Control (UAC) prompt to authorise its execution. Targeted files are appended with .sage extension and a ransom note is created in the same directory as the encrypted files.
Remediation steps
Last edited: 17 February 2020 11:38 am