HomeinetHC7 Ransomware: New variant of HC6 spreads via PsExec

HC7 Ransomware: New HC6 Variant Spreads via PsExec

A new ransomware named HC7 has appeared and is infecting computers via remote desktop services.

HC7 Ransomware

In essence, this is a new version of HC6, a virus that was discussed a lot on forums in November in order to find a solution to deal with it. Michael Gillespie of ID Ransomware managed to create a tool (decryptor) that was able to unlock encrypted files infected by HC6. The ransomware's creators, in response to this, released an improved version, HC7. Let's take a closer look at how it works:

As mentioned above, HC7 uses vulnerable remote desktop services to be able to penetrate a system. Then, it targets the PsExec.exe file. PsExec is a very powerful tool that can be used for good and bad purposes. Its function is almost the same as that of Telnet with the only difference that it gives complete control of the computer as someone can remotely install applications and execute commands without the intervention of any special software. Taking advantage of this, the hacker encrypts over 250 different file types on all accessible computers on a network and gives them the extension “.GOTYA”. Then, a notification appears asking you to send an amount (almost always in Bitcoin) in order to unlock your files.

The process of decrypting and recovering data from HC7 ransomware was provided by a security consultant and published (https://yrz.io/decrypting-hc7) a few days ago. We remind you that when using remote desktop services, it is a good idea to use a VPN and Firewall program for more security.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS