Summary
MegaLocker (also known as NamPoHyu) is a newly observed ransomware tool.
Threat details
At the time of publication, MegaLocker is delivered directly to target systems by the group operating it. They first scan the internet for devices with open ports before deploying several exploits to gain access. They will then attempt to laterally traverse the network these devices are connected in order to identify any network-attached storage devices or Samba instances
Once identified, the group will attempt to gain access to these using brute-force attacks before deploying MegaLocker to encrypt all available files.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
Update A free decryptor for MegaLocker is available online. Users and organisations should be aware that NHS Digital do not test or validate recovery tools and that they use them at their own risk. |
Last edited: 14 February 2020 2:48 pm