UNNAM3D Ransomware
A new ransomware variant known as UNNAM3D has been observed on a number of dark web sites and hacking forums.
Summary
A new ransomware variant known as UNNAM3D has been observed on a number of dark web sites and hacking forums.
Affected platforms
The following platforms are known to be affected:
Threat details
UNNAM3D is delivered via spam emails disguised as Adobe Flash Player updates. These emails contain a link to a script which will download and install UNNAM3D when clicked.
Unlike most ransomware, UNNAM3D will not perform any encryption, instead using an embedded version of the WinRAR utility to move targeted files to password-protected archives. It will then display a ransom note demanding payment in exchange for the archive passwords.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:45 pm