Annabelle Ransomware
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Annabelle is delivered via several different methods including free software downloads, spam email and malicious websites. When first run it will configure itself to start when the user logs in before terminating a number of programs. Annabelle then configures Image File Execution registry entries to disable the same set of programs from running. Attached USB drives are infected using autorun.inf files.
A static key is used for encryption, with encrypted files being appended with the extension .ANNABELLE. Once the encryption process is completed, the master boot record of the device is replaced, resulting in the affected device displaying a screen thanking several people when rebooted.
Remediation steps
| Type | Step |
|---|---|
Identifying the source of infection: Identifying the infected machine and unplugging / disconnecting or quarantining it from the network is essential to damage limitation.
To limit the damage of ransomware and enable recovery: All critical data must be backed up, and these backups must be sufficiently protected/kept out of reach of ransomware.
The only guaranteed way to recover from a ransomware infection is to restore all affected files from their most recent backup. |
Last edited: 17 February 2020 12:36 pm