Rapid Ransomware
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Such emails have been observed claiming to be from the United States' Internal Revenue Service, but with a UK email address and an attachment in German. It attempts to persuade the user that they are in tax arrears and to open the zipped attachment to view a report on how much is owed.
The zip file contains a Word document with a malicious macro that will download and execute the ransomware when enabled. Encrypted files are appended with the .rapid extension.
When encryption is completed, numerous ransom notes are opened in Notepad instructing the user to contact an email address in order to receive payment instructions.
Rapid maintains persistence by adding a registry item to the affected system, which allows it to encrypt new files as they are made.
Remediation steps
Last edited: 17 February 2020 12:53 pm