HomeSecurityPXJ Ransomware deletes backups, making file recovery difficult

PXJ Ransomware deletes backups, making file recovery difficult

A new ransomware strain , named Pxj, which encrypts users' files , was recently discovered by security researchers . The encrypted files, which have the extension ".pxj,"

The new ransomware strain was discovered by IBM 's X-Force Incident Response team and the malware is known as "XVFXGW".

PXJ Ransomware

The malware discovered appears to be new, as it does not show links to any other known ransomware family.

Cybercriminals are using an open-source called UPX, which is known for supporting multiple file formats.

The exact method of distribution of the ransomware remains unknown, but it is mainly done via emails. Once it enters the victim's system, it checks the Recycle Bin and empties it.

It then destroys backups, disables the Windows Error Recovery service, and then executes commands to destroy the user's ability to recover data after encryption.

Once these services are disabled, the encryption process begins, using AES and RSA algorithms.

RansomwarePXJ Ransomware deletes backups, making file recovery difficult

Ransomware encrypts files such as photos and images, databases, documents, videos, and other files on the device.

Once the encryption is complete, it adds a “PXJ” extension and downloads a file named “LOOK.txt” which contains the ransom note demanding a ransom from the victim.

Infected users can only contact the attackers via email and are asked to pay a ransom amount in bitcoins to get their files back.

The attacker also asks victims to pay the ransom immediately, otherwise the amount doubles after three days and the decryption key will be destroyed.

The researchers noticed the existence of a file named “Res.AAABANIx93RdufO4,” which contains old and new samples of the ransomware, which the victim receives, as the note notes, “should not delete this file, which leads to the conclusion that this file can be used in the decryption process.”

The use of ransomware has become a highly profitable business for malicious actors around the world, which is constantly growing and bringing in millions of dollars for its creators.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS