GetCrypt Ransomware
GetCrypt is a newly observed ransomware being installed on machines compromised with the RIG exploit kit.
Summary
GetCrypt is a newly observed ransomware being installed on machines compromised with the RIG exploit kit.
Affected platforms
The following platforms are known to be affected:
Threat details
When executed, GetCrypt checks the Windows language settings and terminates if the language is set to Ukrainian, Belarusian, Russian, or Kazakh. Otherwise, the ransomware will clear the Shadow Volume Copies before scanning the computer for files to encrypt.
GetCrypt will attempt to encrypt any available network shares and will attempt to brute-force any it cannot readily access.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery: Multiple backups should be created including at least one off-network backup (e.g. to tape). Files encrypted by GetCrypt can be recovered using a decryptor available from Emsisoft. Please note that NHS Digital do not verify or endorse these tools and organisations use them at their own risk. |
Last edited: 14 February 2020 2:47 pm