FuxSocy Ransomware
FuxSocy (also known as FuxSocy Encryptor) is newly observed ransomware tool based on the older Cerber malware-as-a-service.
Summary
FuxSocy (also known as FuxSocy Encryptor) is newly observed ransomware tool based on the older Cerber malware-as-a-service.
Affected platforms
The following platforms are known to be affected:
Threat details
Despite these similarities, there is believed to be no association between FuxSocy's operators and the group behind Cerber. At the time of publication, it is unclear how FuxSocy is delivered, although there are unconfirmed reports indicating it may be distributed via spam email campaigns.
Once installed, FuxSocy will perform extensive checks to verify if it is running in a virtual environments. It will then attempt to encrypt all non-system files using an unknown algorithm. Like Cerber, it will prioritise the encryption of folders matching a hard-coded list. However, FuxSocy will only begin encryption of each file starting at 0x708 bytes, resulting in some files remaining partially usable after encryption.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:57 pm