HomeSecurityWe Are Safe: New Enigma Ransomware Targets Only Russian Users

We Are Safe: New Enigma Ransomware Targets Only Russian Users

AVG security researcher Jakub Kroustekhas discovered a new ransomware targeting only Russian-speaking users called Enigma, which, under certain conditions, can allow users to recover some of their files using Shadow Volume Copies.

We Are Safe: New Enigma Ransomware Targets Only Russian Users

As analyzed by researchers from MalwareHunterTeam and Bleeping Computer, the ransomware encrypts files with the current de-facto AES-RSA double encryption standard and then stores the encryption key on the computer's desktop in the form of a file called ENIGMA_[NUMBER].RSA.

If users want the decryption, they will have to pay the crooks 0.4291 Bitcoin, which is approximately $200. As with other ransomware families, payment must be made by accessing a browser on the Tor network, via the Tor Browser. On the payment site, you will be asked to upload the file mentioned above.

The current ransomware is via plain HTML files. In recent months, security researchers have seen a surge in ransomware families that install themselves via JavaScript code. One such case is Enigma. When users open the HTML file, the malicious code contained within it executes and offers another Javascript file to download.

Users who execute this JavaScript file will launch another malicious function that builds an EXE file on the local computer and, in turn, starts executing the EXE. This executable is the Enigma ransomware, which immediately begins encrypting files. Once it does, it creates and executes an HTA file, which is the ransom note. This file is set to start with the operating system.

ransom note

As for the possibility of decrypting files, this is a simplified explanation of what will happen towards the end of the encryption process that you should only remember in case you double-click on an HTA file.

Apparently, for users who have Windows UAC (User Account Control) enabled, the ransomware will display a UAC prompt at some point towards the end of the encryption process.

If users click “No” to this message, the ransomware encryption routine ends without deleting the Shadow Volume Copies. The files will remain encrypted, however, you will be able to identify them based on their “.enigma” extension. To recover your files, there is specialized hard drive recovery software that can extract data from Shadow Volume Copies.

So, today's moral is that we should leave Windows UAC enabled, which is something security researchers have been saying for years. As previously mentioned, the ransomware is only targeting Russian users. For now!

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS