Summary
Kupidon is newly-observed ransomware that targets Windows systems.
Affected platforms
The following platforms are known to be affected:
Threat details
The method by which Kupidon spreads is not known at the time of publication, but it is considered likely to be exploiting exposed remote desktop servers.
When the threat actors gain access to a system they manually encrypt files. Encrypted files are renamed with '.kupidon' in the extension. A ransom note named !KUPIDON_DECRYPT.TXT demanding payment in bitcoin is saved. The ransom note content changes depending on whether the affected system belongs to a business or an individual.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting files, which may also include remote files on network locations. The only guaranteed way to recover from a ransomware infection is to restore all affected files from their most recent backup. To reduce the likelihood of infection by ransomware, NHS Digital advises that:
Please note that NCSC maintains guidance for securely configuring a wide range of end user device (EUD) platforms. For further details refer to their end user device security guidance pages. To limit the impact of a ransomware infection, NHS Digital advises that:
|
Indicators of compromise
Last edited: 29 June 2021 12:01 pm