Tycoon Ransomware
First observed in December 2019, Tycoon is a multiplatform Java-based ransomware tool primarily targeting software supply-chain organisations in the USA and Western Europe.
Summary
First observed in December 2019, Tycoon is a multiplatform Java-based ransomware tool primarily targeting software supply-chain organisations in the USA and Western Europe.
Affected platforms
The following platforms are known to be affected:
Threat details
Tycoon is delivered manually by the group operating it through exposed Remote Desktop Services ports. Prior to delivery, the group performs extensive network reconnaissance and disables a number of security services. Tycoon is then deployed to all network-connected systems.
Once deployed, Tycoon will attempt to encrypt all file in directories matching a hardcoded list using a hybrid AES-RSA implementation.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting files, which may also include remote files on network locations. The only guaranteed way to recover from a ransomware infection is to restore all affected files from their most recent backup. To reduce the likelihood of infection by ransomware, NHS Digital advises that:
Please note that NCSC maintains guidance for securely configuring a wide range of end user device (EUD) platforms. For further details refer to their end user device security guidance pages. To limit the impact of a ransomware infection, NHS Digital advises that:
|
Indicators of compromise
Last edited: 31 January 2022 8:36 am