Summary
First observed in 2016, Nuke is a ransomware tool targeting organisations globally.
Affected platforms
The following platforms are known to be affected:
Threat details
Nuke is delivered disguised as popular third-party applications via spam campaigns.
Once installed, Nuke will attempt to disable or remove any security or recovery services; before encrypting all local non-system files using an AES-256 algorithm, the key for which is then encrypted using RSA-2048.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting files the logged-in user has permission to modify, which may also include remote files on network locations. The only guaranteed way to recover from a ransomware infection is to restore all affected files from their most recent backup. Please note that the NCSC maintains guidance for securely configuring a wide range of end user device (EUD) platforms. For further details refer to their end user device security guidance pages. To reduce the likelihood of infection by ransomware, NHS Digital advises that:
To limit the impact of a ransomware infection, NHS Digital advises that:
|
Indicators of compromise
Last edited: 29 June 2021 12:00 pm