VCrypt Ransomware
VCrypt is a newly observed ransomware tool targeting Western Europe. Unlike most ransomware, VCrypt does not encrypt files.
Summary
VCrypt is a newly observed ransomware tool targeting Western Europe. Unlike most ransomware, VCrypt does not encrypt files.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how VCrypt is distributed, although there are unconfirmed reports indicating it may be delivered via spam email campaigns.
Once installed, VCrypt will unpack an embedded copy of the 7zip archiving utility, which it then uses to create multiple password-protected archives of specific directories. When complete, it attempts to delete all files contained on other drive letters before posting a ransom note
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting files, which may also include remote files on network locations. The only guaranteed way to recover from a ransomware infection is to restore all affected files from their most recent backup. To reduce the likelihood of infection by ransomware, NHS Digital advises that:
Please note that NCSC maintains guidance for securely configuring a wide range of end user device (EUD) platforms. For further details refer to their end user device security guidance pages. To limit the impact of a ransomware infection, NHS Digital advises that:
|
Indicators of compromise
Last edited: 29 June 2021 12:01 pm