The new HelloFire ransomware threat pretends to be a security auditor and locks users' systems
See also: Over 40 countries to sign to stop paying ransoms to ransomware gangs

This new player in cyberspaceuses deceptive tactics to disguise its malicious intentions as legitimate penetration testing activities.
Disguise as penetration testing
The “HelloFire” ransomware is a recent addition to the cybercrime landscape and is unique due to its lack of a traditional leak website or the usual ransomware branding.
The ransom note clearly indicates that the threat actor is pretending to be a pentester (security auditor) – a tactic previously observed by other cybercriminals.
The use of specific email domains in the ransom note, however, such as “ keemail.me ” and “ onionmail.org ,” undermines the credibility of the attack as a legitimate security test. These domains have been associated with various threat actors since 2013.
ShadowStackRE shared an article about the emergence of a new threat landscape called Hellofire Ransomware.
See also: Hive ransomware: 10 million reward for information on its members

Possible Russian Threat Agent
The ransomware note and PDB (Program Database) path contain references to the word “hello” in both English and Russian (“Zdravstvuy”), suggesting a possible Russian connection.
The encrypted files have the extension “.afire”, and the ransom note is located in a “Restore.txt” file.
HelloFire ransomware has an extensive list of services, directories, and files that it targets, suggesting a well-documented approach for maximum impact on infected systems.
The ransomware starts a supplied cryptographic identifier and uses the Windows API to manage the random number generator. It then suspends system recovery by deleting Windows, stopping a list of services and programs, and emptying the Recycle Bin.
A new thread is created to manage the file encryption and discovery process, which includes enumerating the volume drives and shared files associated with the target machine.
HelloFire ransomware represents a highly sophisticated and exemplary threat that exploits the appearance of legitimate security tests to carry out attacks .
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Knight ransomware: Source code for sale

What are the most successful methods of protection against ransomware?
One of the most successful methods of protecting against ransomware, such as HelloFire, is user education. Users should be aware of the techniques used by attackers, such as phishing, and know how to recognize suspicious emails and links. Using up-to-date security software is also crucial. Creating and maintaining regular backups of important data is another important method of protection. Finally, using tools to restrict access rights can help protect against ransomware.
Source: gbhackers
