[F]Unicorn Ransomware
[F]Unicorn is a newly observed ransomware tool targeting users throughout Western Europe.
Summary
[F]Unicorn is a newly observed ransomware tool targeting users throughout Western Europe.
Affected platforms
The following platforms are known to be affected:
Threat details
It is currently delivered in email spam campaigns using a number of Covid-19 related lure documents purporting to be from government or healthcare organisations
When executed, [F]Unicorn displays a fake version of the Johns Hopkins University CSSE COVID-19 Dashboard, whilst encryption of all local non-system files occurs in the background
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting files, which may also include remote files on network locations. The only guaranteed way to recover from a ransomware infection is to restore all affected files from their most recent backup. To reduce the likelihood of infection by ransomware, NHS Digital advises that:
Please note that NCSC maintains guidance for securely configuring a wide range of end user device (EUD) platforms. For further details refer to their end user device security guidance pages. To limit the impact of a ransomware infection, NHS Digital advises that:
|
Indicators of compromise
Last edited: 29 June 2021 12:01 pm