Summary
PXJ, also known as XVFXGW, is ransomware first observed in early 2020.
Affected platforms
The following platforms are known to be affected:
Threat details
The means by which PXJ is spread is not known at the time of publication.
When PXJ is executed it first hinders file recovery by emptying the recycle bin, deleting volume shadow copies and disabling the Windows Error Recovery Service. PXJ then encrypts documents, databases and media files on the affected device using the AES algorithm. The PXJ extension is appended to affected filenames. The AES encryption key is then itself encrypted using the RSA algorithm.
A ransom note named LOOK.txt is saved to the system that demands payment in bitcoin within 7 days to recover the affected files.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting files the logged-in user has permission to modify, which may also include remote files on network locations. The only guaranteed way to recover from a ransomware infection is to restore all affected files from their most recent backup. Please note that NCSC maintains guidance for securely configuring a wide range of end user device (EUD) platforms. For further details refer to their end user device security guidance pages. To reduce the likelihood of infection by ransomware, NHS Digital advises that:
To limit the impact of a ransomware infection, NHS Digital advises that:
|
Indicators of compromise
Last edited: 29 June 2021 12:01 pm