HomeSecurityNew Hog ransomware decrypts victims' files only if they connect to Discord...

New Hog ransomware decrypts victims' files only if they connect to its developer's Discord server

A new ransomware called “Hog” encrypts the devices of unsuspecting users and decrypts them only if they connect to its developer’s Discord server. A few days ago, MalwareHunterTeam discovered a (work-in-progress) decryptor for the Hog ransomware, which asks victims to connect to the hackers ’ Discord server to decrypt their files .

New Hog ransomware decrypts victims' files only if they connect to its developer's Discord server
New Hog ransomware decrypts victims' files only if they connect to its developer's Discord server

BleepingComputer spotted the ransomware's encryption component [VirusTotal], which, when executed, checks for the presence of a specific Discord server. If it does, it begins encrypting victims' files. While encrypting victims' files, it appends the .hog and automatically extracts the decryption component.

Once the ransomware has finished encrypting the device, it will launch the decryption program DECRYPT-MY-FILES.exe from the Windows Startup folder.
This decryptor will explain to victims exactly what happened and then ask them to enter their Discord user token.

New Hog ransomware decrypts victims' files only if they connect to its developer's Discord server
New Hog ransomware decrypts victims' files only if they connect to its developer's Discord server

A Discord token allows the ransomware to verify Discord's APIs and to check if someone has connected to its server. If a victim has connected to the server, the ransomware will decrypt its files using a static key that is embedded in the ransomware.

New Hog ransomware decrypts victims' files only if they connect to its developer's Discord server
New Hog ransomware decrypts victims' files only if they connect to its developer's Discord server

Hog appears to be an ongoing ransomware, and simultaneously its case demonstrates that threat actors are increasingly using Discord for malicious activities.

New Hog ransomware decrypts victims' files only if they connect to its developer's Discord server
The new Hog ransomware decrypts victim files only if they connect to the developer's Discord server

Additionally, Trend Micro recently discovered another ransomware, dubbed “Humble,” which uses a webhook to post information about new victims to the malicious actor’s Discord server.

It is worth noting that Discord is commonly used by threat actors to distribute malware or collect stolen data . As malicious actors increasingly turn to Discord, it is important for network administrators and security tools to monitor Discord traffic for threats or other abnormal behavior.

Source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS