This article was originally published by 8btc and written by Vincent He.
A ransomware virus named Ryuk has spread to China, asking the users of infected devices for a hefty bitcoin ransom.
Tencent Security reported on July 17, 2019, that it has monitored Ryuk and found that it encrypts data on an infected device and demands a ransom in bitcoin. The ransom is generally very high and has recently reached 11 BTC.
The virus disables victims’ systems with sophisticated ransomware, mainly through botnets. First found in North America, it uses RSA and AES encryption algorithms to encrypt victims’ files. The campaign appears highly targeted, with government and enterprise institutions as preferred victims.
Ryuk originated in the Hermes date code family, and the earliest signs of its activity can be traced back to August 2018. It makes use of most of the Hermes code, has the same white list filtering mechanism as a Hermes virus and it also uses Hermes strings, even for the unique infection marker of files.
The sample found in China releases and runs different blackmail modules, which will help the virus implement subsequent injection and further improve the efficiency of its operation. As part of the most recent attacks, a dropper containing both the 32-bit and 64-bit modules of the ransomware was used. When run, Ryuk checks if it was executed with a specific argument and then kills more than 40 processes and over 180 services belonging to antivirus, database, backup and document editing software.
The blackmail letter left by Ryuk is very simple, with only two blackmail contact mailboxes and blackmail virus names. It does not take long after being answered that the attacker requests a BTC ransom.
Almost all of the observed Ryuk ransomware samples, the security researchers say, were provided with a unique wallet. Shortly after a recent victim paid the ransom, the attackers divided the funds and transmitted them through multiple accounts.
The ransomware also remains on the infected machines and attempts to encrypt network resources in addition to local drives. It also destroys its encryption key and deletes shadow copies and various backup files from the disk to prevent users from recovering files.Earlier this month, Tencent Security reported another Trojan virus called Burimi that has hacked over 33 million email accounts demanding a bitcoin ransom.
The post The Ryuk Virus Is Spreading Through China, Asking 11 BTC Ransoms appeared first on Bitcoin Magazine.
Energy production and its surrounding industry will experience a major shift in operations as Bitcoin becomes a driving force of profit.The energy sector is seeing a complete paradigm shift:Bitcoin’s monetary network effectMonetization of energyLeads to an arms race of energy tech becoming more and more efficient and productiveCheap energy production allows for cheap energy utilizationCheap…
Making sure your bitcoin transactions remain private is made significantly easier with a computer dedicated to this function alone.This is an opinion editorial by Arman The Parman, a Bitcoin educator passionate about privacy and contributor to Bitcoin Magazine.What’s Wrong With Using A Regular Computer?When making bitcoin transactions, it’s ideal if your computer has no malware.…
The hostage holding that regulatory bodies impose upon businesses punishes consumers in various ways.Audio recording of this article here.Big business is an extension of the state.Governments control businesses and their customers, and their weapon of choice is legislation. The resulting regulations are so broad and arbitrary that the government can harass businesses until they comply…
Listen To This Episode: AppleSpotifyGoogleLibsynOvercast In this episode of Bitcoin Magazine’s “Fed Watch,” Christian Keroles and Ansel Lindner discussed the recent events around r/wallstreetbets (WSB) and GameStop from a macro perspective. They spent some time setting up the history and what transpired, before diving into the meanings and implications of what happened. They tried to…
Malcolm CaSelle, a pioneering blockchain technology and Bitcoin entrepreneur, has died at age 50, according to a social media post from friend and colleague E. David Ellington. “My younger brother, business partner, advisor and friend, Malcolm CasSelle, died in Mexico yesterday,” Ellington wrote on November 18, 2020. “Apparently, his friends said he had a stomach…
Two years since the U.S. sent COVID-19 stimulus checks to taxpayers, investment in bitcoin mining stocks has generated significant returns.The two-year anniversary of the first of three coronavirus economic impact payments (aka, stimulus “stimmy” checks) deposited in U.S. taxpayers’ bank accounts came and went on April 11, and headlines about monetary inflation, possible economic recession…
The first ever bitcoin-based ETF in the United States has started trading this morning, amassing $250 million in 15 minutes.First bitcoin ETF in the U.S. has gone live in the NYSE under the ticker BITO.The ProShares Bitcoin Strategy ETF invests in bitcoin futures instead of holding actual spot BTC.A second bitcoin futures ETF is set…
A recent visit to El Salvador shows that heavy-handed government efforts are clashing with Bitcoin’s self-sovereign and community-focused ethos.Embracing Bitcoin is a bold move and a great chance for countries like El Salvador, but the end doesn’t justify the means. Bitcoiners are being played for President Nayib Bukele’s power fantasies of a new Bitcoin City,…
After a year on its testnet, the VeriBlock blockchain went live yesterday on the Bitcoin mainnet, allowing exchanges, wallet providers, merchants and other crypto businesses to leverage Bitcoin’s robust blockchain security. Now that it’s live on the mainnet, VeriBlock’s model extends the Bitcoin blockchain’s security protection from 51-percent attacks to non-Bitcoin blockchains by linking them…