AnteFrigus Ransomware
AnteFrigus is a newly observed ransomware tool that targets specific drive locations.
Summary
AnteFrigus is a newly observed ransomware tool that targets specific drive locations.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, AnteFrigus is solely delivered by the RIG exploit kit via redirects from the Hookads malvertising campaign.
Once installed, AnteFrigus, will attempt to encrypt files on the D, E, F, G, H, and I drives; and will avoid encrypting any files with extensions matching a hard-coded exclusion list.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:55 pm