Planetary Ransomware
Planetary Ransomware is a family of ransomware variants. It takes its name because it commonly uses the names of planets in the extensions appended to the names of encrypted files.
Summary
Planetary Ransomware is a family of ransomware variants. It takes its name because it commonly uses the names of planets in the extensions appended to the names of encrypted files.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unknown how Planetary variants are delivered. As with most ransomware, it is likely to be distributed via spam email.
Once installed, Planetary variants will encrypt local files and append the following extensions:
- .mira
- .Neptune
- .Pluto
- .yum
Remediation steps
| Type | Step |
|---|---|
|
A free decryption tool for this ransomware family has been released, however it is untested by NHS Digital and users can use it at their own risk. If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:49 pm