Summary
LooCipher is a newly observed ransomware tool.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how LooCipher is delivered, although there are unconfirmed reports suggesting it may be distributed in spam or phishing campaigns.
When executed, LooCipher will create a file on the affected system's desktop containing a unique ID, bitcoin address and an encryption key expiration timer. It will then begin to encrypt all non-system files on the system, appending them with an lcphr extension. LooCipher will not delete the original files but instead converts them 0 byte files.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
Update Cybaze-Yoroi Z-Lab has released an open-source decryption tool able to recover files encrypted by LooCipher. Organisations are reminded that NHS Digital do not test or verify recovery tools, and that they use them at their own risk. |
Last edited: 14 February 2020 2:49 pm