Matrix Ransomware
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Matrix has been distributed using a range of methods including spam email campaigns, the RIG exploit kit and hacked remote desktop services.
When Matrix is executed it encrypts the user's files and filenames, including on network shares. Filenames may be appended with a number of extensions. Matrix then uploads statistics on the types of files that were encrypted to its command and control server. To undermine recovery by the user Matrix deletes Volume Shadow Copies and disables recovery options on the affected device, with some variants also overwriting all free space on the storage volume. A ransom note is saved which demands payment in Bitcoin.
Some variants of Matrix can propagate further by using shortcuts. During the encryption process, these variants hide a folder and then create a shortcut using the folder's icon and name to fool users into executing the ransomware. These malicious shortcuts are created on network shares and removable drives, which can result in the ransomware being executed across the local network.
Threat updates
| Date | Update |
|---|---|
| 21 Aug 2018 |
A new Matrix variant, known as Fox, has been observed using a new encrypted file extension |
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
If Remote Desktop Protocol (RDP) is not used, then ensure port 3389 (TCP/UDP) is blocked at your internet firewall. If RDP is used, then:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 17 February 2020 12:48 pm