INPIVX Ransomware Service
INPIVX is a newly observed service offering buyers access to a comprehensive ransomware tool and control dashboard. Unlike other ransomware-as-a-service tools, the group operating INPIVX do not offer hosting or delivery services.
Summary
INPIVX is a newly observed service offering buyers access to a comprehensive ransomware tool and control dashboard. Unlike other ransomware-as-a-service tools, the group operating INPIVX do not offer hosting or delivery services.
Affected platforms
The following platforms are known to be affected:
Threat details
The service is intended for non-technical buyers to run their own campaigns by supplying them with the source-code for the ransomware and the dashboard for a set price; although they will still have to distribute the malware themselves.
INPIVX's malware is written in C++ and is fully customisable by buyers, with only the encryption algorithm (AES encryption using RSA encrypted keys) being identical across all versions. A decryption tool is also provided. The PHP-based dashboard shows buyers information including ransomware installations, number of encrypted files and affected systems as well as user and system information for each affected device.
As INPIVX's source code is readily available for purchase, it is likely that other attackers will begin to use it in their future campaigns.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:46 pm