HomeSecurityGoodWill ransomware: Its goal is to get victims to donate to the poor

GoodWill ransomware: Its goal is to get victims to donate to the poor

GoodWill ransomware was detected by CloudSEK researchers in March 2022. As the threat group's name suggests, its operators are reportedly interested in promoting social justice rather than conventional financial reasons.

See also: Hackers use deep fake videos of Elon Musk in crypto scam

GoodWill ransomware

A new ransomware strain has been detected in India that tricks victims into donating clothes to the homeless and providing financial assistance to anyone in need of urgent medical care but unable to afford it, according to digital risk monitoring firm Cloudsek. The firm warned that the Goodwill ransomware could lead to both temporary, and possibly permanent, loss of corporate data and a potential shutdown of company operations and accompanying loss of revenue.

See also: Sberbank says it faces huge waves of DDoS attacks

After infection, the GoodWill ransomware worm encrypts documents, photos, videos, databases , and other important files and makes them inaccessible without the decryption key.

The hackers suggest that victims do three social activities in exchange for the decryption key – donate clothes to the homeless, record the action and post it on social media, take five underprivileged children to Dominos Pizza Hut or KFC and treat them, take photos and videos and post them on social media, and provide financial assistance to anyone who needs urgent medical care but cannot afford it, at a nearby hospital, record an audio document and share it with the operators,” the report said.

Once all three activities are completed, the ransomware asks victims to make a post on social media (Facebook or Instagram) about “how you transformed yourself into a kind human being by becoming a victim of a ransomware called GoodWill.”

GoodWill ransomware: Its goal is to get victims to donate to the poor

See also: Microsoft: Huge increase in Linux XorDDoS malware activity

Upon completion of all three activities, ransomware operators verify the media files shared by the victim and their social media posts

The hacker will then share the full decryption kit that includes the main decryption tool, the password , and a video tutorial on how to recover all important files, the report said.

"Our researchers were able to trace the email address provided by the ransomware group to an solutions and services company that provides end-to-end managed security services," the report said.

Information source: businessinsider.in

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS