Ransomware

Thx Ransomware is a Dharma Family Member Prone to Encrypting Essential Files screenshot

Thx Ransomware is a Dharma Family Member Prone to Encrypting Essential Files

Thx belongs to the Dharma ransomware family and focuses on encrypting data as its primary objective. During the encryption process, Thx incorporates specific identifiers into the original filenames, such as the... Read more

June 7, 2023
Neqp Ransomware is a Djvu Variant Seeking Files to Encrypt screenshot

Neqp Ransomware is a Djvu Variant Seeking Files to Encrypt

Neqp is a type of ransomware that is part of the Djvu clone family. This new variant is designed to infiltrate a victim's system and encrypt nearly all files stored on its drives. The encryption process targets a wide... Read more

June 5, 2023
Weqp Ransomware Locks Victim Systems screenshot

Weqp Ransomware Locks Victim Systems

After carefully analyzing malware samples, our team of experts specializing in malware detection has identified a new variant called Weqp, which belongs to the Djvu ransomware family. Weqp functions by encrypting data... Read more

June 1, 2023
xCor Ransomware Locks Victim Systems screenshot

xCor Ransomware Locks Victim Systems

xCor is a form of ransomware created with the intention of encrypting files, altering their names by adding the victim's ID, xcorp@decoymail.mx email address, and appending the ".xCor" extension. This malicious... Read more

May 30, 2023
Buhti Ransomware Aims for Victims Running Both Windows and Linux screenshot

Buhti Ransomware Aims for Victims Running Both Windows and Linux

Buhti is a type of ransomware that targets both Windows and Linux systems. While the Buhti ransomware payload primarily focuses on Windows computers and is a variant of the previously leaked LockBit 3.0 ransomware... Read more

May 29, 2023
8Base Ransomware Locks Victims' Files screenshot

8Base Ransomware Locks Victims' Files

8base Ransomware is classified as a type of ransomware that encrypts data. When a computer becomes infected with 8base Ransomware, all files on the compromised system, including .xtml, .doc, .png, .pdf, .asp, and... Read more

May 26, 2023
NoEscape Ransomware Will Render Your Files Unreadable screenshot

NoEscape Ransomware Will Render Your Files Unreadable

NoEscape operates as a Ransomware-as-a-Service, catering to other criminals who act as affiliates or customers. The ransomware builder interface allows affiliates to customize various configurations while creating the... Read more

June 6, 2023
Neon Ransomware Will Lock Your System screenshot

Neon Ransomware Will Lock Your System

Our researchers discovered the Neon ransomware variant, which is another member of the numerous Djvu ransomware clone family. Neon encrypts files on victim systems and makes them inaccessible. Files encrypted by Neon... Read more

June 5, 2023
Werz Ransomware Will Encrypt Your Drives screenshot

Werz Ransomware Will Encrypt Your Drives

During our analysis of new malware samples, we came across a variant of the Djvu ransomware family called Werz. This particular ransomware encrypts files and alters their original filenames by adding the ".werz"... Read more

May 31, 2023
Tiywepxb Ransomware Will Encrypt Your Files screenshot

Tiywepxb Ransomware Will Encrypt Your Files

Tiywepxb, a member of the Snatch ransomware family, was identified by our team of malware researchers while analyzing new malware samples. Its main objective is to encrypt files, appending the ".tiywepxb" extension to... Read more

May 30, 2023
Moneybird Ransomware Used in Attacks on Israeli Entities screenshot

Moneybird Ransomware Used in Attacks on Israeli Entities

Agrius, an Iranian hacking group also known as Pink Sandstorm and formerly Americium, has developed a new type of ransomware called Moneybird. CheckPoint researchers discovered this dangerous malware, which signifies... Read more

May 26, 2023
Vapo Ransomware Will Lock Your System screenshot

Vapo Ransomware Will Lock Your System

During our evaluation of recently submitted malware samples, our team uncovered Vapo, a member of the Djvu ransomware family. Vapo operates by encrypting files on the victim's computer and demands a ransom payment in... Read more

May 25, 2023
Nerz Ransomware is Based on Djvu Code to Target Random Files screenshot

Nerz Ransomware is Based on Djvu Code to Target Random Files

During our analysis of malicious file samples, our team recently came across a variant of the Djvu ransomware family called Nerz. Similarly to its counterparts, Nerz encrypts data but adds the ".nerz" extension to the... Read more

June 6, 2023
DarkRace Ransomware Locks Victim's Files screenshot

DarkRace Ransomware Locks Victim's Files

Security researcher S!Ri recently uncovered DarkRace, a type of ransomware that operates by encrypting files. As part of its malicious actions, the malware adds its own extension (".1352FF327") to the original... Read more

June 2, 2023

Weon Ransomware Encrypts Many File Types

Our team has recently discovered a new variant of the Djvu ransomware family called Weon. Weon is a malicious software, also known as ransomware, that employs encryption techniques to lock files, rendering them... Read more

May 31, 2023
EXISC Ransomware Targets Corporations and Businesses screenshot

EXISC Ransomware Targets Corporations and Businesses

During our investigation of new submissions on the VirusTotal site, we came across a ransomware program called EXISC. Its primary purpose is to encrypt data and demand payment in exchange for decrypting it. Upon... Read more

May 29, 2023
Vatq Ransomware Seeks Files to Encrypt Causing System Damage screenshot

Vatq Ransomware Seeks Files to Encrypt Causing System Damage

During our examination of new malware sample, our team made a discovery involving the Vatq ransomware, which belongs to the Djvu ransomware family. Once a computer is infected, Vatq proceeds to encrypt files and... Read more

May 26, 2023
Vaze Ransomware is a Djvu Clone Seeking Destruction of Files screenshot

Vaze Ransomware is a Djvu Clone Seeking Destruction of Files

During our examination of malware samples, we encountered a variant of the Djvu ransomware family known as Vaze. This specific ransomware operates by encrypting files and altering their original filenames by adding... Read more

May 25, 2023
Loading...