The MalwareHunter team discovered a new Ransomware, the Ryuk Ransomware , that tracks the IP address of the computer and blacklists computers so that if matching computers are detected, they are not encrypted. The team also discovered that there were some changes to the ransomware that had not been observed in previous ones.

Vitali Kremez, a security researcher at Malware Hunter, found that the ransomware checks the output of arp -a for specific IP addresses and if they are found, it will not encrypt the computer. In addition to blacklisting IP addresses, this new Ryuk variant will also compare the computer name with “SPB”, “Spb”, “spb”, “MSK”, “Msk” and “msk”. If the computer name contains any of these, Ryuk will not encrypt the computer.
The reason all these checks are being done, according to Kremez, is to prevent computer encryption in Russia.

In any case, it is wise to have a backup of your files, because ransomware can actually cause problems if the backups cannot be recovered. These also need to be stored in a place and in a way that they are not affected by ransomware.
In addition, ransomware can be transmitted via Trojans , and for this reason, users should be aware of basic security rules. For example, before opening an email , they need to be sure of the sender and if they do not know him, they should not open their attachments. In the past, it has been observed that the target was mainly the copies that users kept as back up, in case of emergency.
Finally, your network may make Remote Desktop services publicly accessible, which could cause you problems in the future. Instead, these services should only be accessible via VPN to be as protected as possible.
