Aurora Ransomware
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Like most other ransomware, Aurora is distributed via malicious spam email attachments. When a user executes Aurora it encrypts their files and appends them with either the .Aurora or .desu extensions. Files may also be renamed to the hexadecimal code of the original filename.
A text file is saved to the user's desktop containing a ransom note demanding payment in Bitcoin. At the time of publication, there is no publicly available tool to decrypt affected files.
Remediation steps
| Type | Step |
|---|---|
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 17 February 2020 12:38 pm