HomeSecurityNew Dharma Ransomware campaign targets Italy

New Dharma Ransomware campaign targets Italy

Dharma Ransomwareis distributed by hackers through a malicious spam targeting Windows in Italy.

Dharma Ransomware has been around for several years and is based on a ransomware called Crysis. However, its distribution via spam messages is not as common, as it has previously been installed via remote desktop services.

Security researchers JAMESWT, TG Soft, and reecDeep discovered this new spam campaign, which infects users with the Ursniff keylogger or Dharma Ransomware.

Spam email messages use subjects such as Fattura n. 637 del 14.01.20 and pretend to be an invoice that has been sent to the user.

The message contains an attached file, which is the purported invoice, and as soon as the user clicks on it, it redirects them to the OneDrive page that hosts a file titled ‘New documento 2.zip’ . This file is automatically downloaded when a user visits the page.

Dharma_ransomware

Inside this zip file there are two other files: a VBS script named ‘Nuovo documento 2.vbs’ and an image file named ‘yuy7z.jpg’.

If the user runs the program “Nuovo documento 2.vbs”, there are various malicious software that may be installed on their device.

Earlier, TG Soft saw the data-being installed by VB script, and then it started installing the Dharma Ransomware.

The version of Dharma Ransomware that is installed adds the .ROGER extension to encrypted files and displays a message demanding a ransom and telling the victim to contact sjen6293@gmail.com for information on how to make the payment.

Unfortunately, there is no way to decrypt the files that have been encrypted by Dharma Ransomware, unless you have the key, which is known only to the operators of the ransomware.

If you have been infected by this ransomware, the only way to recover your files is through backups or by paying the ransom demanded.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS