According to a researcher, the RIG exploit kit is being used by hackers to distribute the new ERIS Ransomware and its payload. A single visit to a page is enough to install the ransomware on vulnerable systems.
The ERIS ransomware was first spotted in May 2019 by Michael Gillespie. At the time, no samples of the software existed. Over the weekend, exploit kit researcher nao_sec (Twitter) discovered that the ransomware was being spread via a malvertising campaign using the RIG exploit kit.
According to researcher nao_sec, the malvertising campaignuses the popcash ad network and redirects users to the RIG exploit kit, as shown below:
The kit will then attempt to exploit a vulnerability in the browser. If successful, it will automatically download and install the ERIS Ransomware on the vulnerable computer.
ERIS Ransomware
Once the ERIS Ransomware is installed, the malware encrypts the files and appends the .ERIS extension, as shown in the image below.

Files that have been encrypted contain an indication that says “FLAG_ENCRYPTED”. This is located at the end of the file and essentially indicates that the specific file is encrypted by ransomware.

The ransomware also creates a note named @ READ ME TO RECOVER FILES @ .txt, which asks the victim to contact Limaooo@cock.li, where they will receive instructions on how to pay. This note also includes a unique ID, which the victim must send to the ransomware developer. This will allow for a free trial decryption of a single file.

Currently, there is no way to decrypt the files affected by the ERIS ransomware for free.
