Backdoor Installed by HelloXD Ransomware , Directed Windows and Linux Devices

This article has been indexed from

CySecurity News – Latest Information Security and Hacking Incidents

 

HelloXD is ransomware that first appeared in November 2021 and does double extortion assaults. Researchers discovered several variations that affect Windows and Linux computers. 
According to a recent analysis from Palo Alto Networks Unit 42, the malware’s creator has developed a new encryptor with unique packing for detection avoidance and encryption algorithm tweaks. This is a substantial deviation from the Babuk code, indicating the author’s goal to create a new ransomware strain with possibilities and characteristics to allow for more attacks. 
HelloXD ransomware threat 
HelloXD first emerged to the public on November 30, 2021, and is based on Babuk’s leaked code, which was published in September 2021 on a Russian-language cybercrime site. 
Palo Alto Networks Unit 42 security researchers Daniel Bunce and Doel Santos said, “Unlike other ransomware, this ransomware does not have an active leak site; instead, it prefers to direct the infected victim to negotiations via Tox chat and onion-based messaging instances.” 
The operators of the ransomware family are no exception since they used double extortion to exto

[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.

Read the original article: