HydraCrypt Ransomware
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
The malware encrypts a user’s files and appends the filenames with the extension “hydracrypt_ID_” suffixed with eight random characters. A plain text file is also dropped with instructions on paying the ransom before the files can be decrypted. The file contains a threat that information may be leaked on dark marketplaces, if the ransom is not paid.
The malware’s impact is more than denying access to sensitive data as at least some data is exfiltrated to a remote host. According to the malware authors, this data could be released if payment is not received, suggesting the malware could also lead to a subsequent compromise in the data’s confidentiality.
A proven decryption software has been released, however, the risk remains moderate due to its use with the Angler Exploit Kit.
The malware initially drops and executes a copy of itself under the folder ChromeSettings2364 in the %AppData% directory, where it is appended with a random name to attempt to evade signature-based detections, and deletes itself. The malware gathers certain information about the target machine and communicates this to a C2 (Command and Control) node.
The ransomware encrypts a wide range of file extensions, excluding .exe, .dll and .sys, with RC4 code. System backups are also encrypted.
Remediation steps
Last edited: 17 February 2020 12:45 pm