Thu, 25 Apr 2024 Today's Paper

‘Sodinokibi’ ransomware CERT issues Red Alert

By

25 May 2020 12:00 am - 0     - {{hitsCtrl.values.hits}}

A A A

By Darshana Sanjeewa Balasuriya

The Sri Lanka Computer Emergency Readiness Team (SLCERT) has issued a high threat warning regarding the onset of an advanced ransomware which targets the IT systems used by corporate entities and individuals worldwide.

‘Sodinokibi’, also known as ‘REvil’ is a name for a family of Advanced Ransomware. It encrypts (makes files and folders unreadable) important files in various formats and demands a ransom to decrypt (make files and folders readable) them.   


‘Sodinokibi’ ransomware first appeared in April 2019. The sole purpose of the ransomware is to encrypt files with a random extension and then demand a ransom to recover the files.   
According to the CERT, the attackers send a ransom note through a text (.txt) file and/or by a message that will appear on the victim’s computer screen. To decrypt data, attackers ask users to visit their website using one of the two links provided; one of which has to be opened using the Tor browser and the other with commonly used browsers. Victims have to provide the key and extension name included in the ransom message. The victim is then informed of the payment details and instructions to be followed.   
‘Sodinokibi’ has attacked a wide array of companies including Telecommunication service providers, Law Firms and IT Services causing service disruptions and information losses. Further, it has targeted celebrities and prominent individuals threatening to release their sensitive information online.   


The CERT advises users to refrain from downloading files from suspicious sources or click on suspicious links.   
“Do not download decryption tools from suspicious sources, regularly make multiple backups of data, and keep them offline and/or store off-site, increase the security of backup with additional ransomware protection software, update and install latest security patches on installed third party software, keep your virus guard and operating system up to date and monitor for latest malware infections and patterns, isolate the infected computers from the network and payment of ransom is not recommended since there is no guarantee that you will get your data back,” CERT said.   

 

  • According to the CERT, the attackers send a ransom note through a text (.txt) file and/or by a message that will appear on the victim’s computer screen

 


Order Gifts and Flowers to Sri Lanka. See Kapruka's top selling online shopping categories such as Toys, Grocery, Kids Toys, Birthday Cakes, Fruits, Chocolates, Clothing and Electronics. Also see Kapruka's unique online services such as Money Remittence,Astrology, Courier/Delivery, Medicine Delivery and over 700 top brands. Also get products from Amazon & Ebay via Kapruka Gloabal Shop into Sri Lanka

  Comments - 0

Order Gifts and Flowers to Sri Lanka. See Kapruka's top selling online shopping categories such as Toys, Grocery, Kids Toys, Birthday Cakes, Fruits, Chocolates, Clothing and Electronics. Also see Kapruka's unique online services such as Money Remittence,Astrology, Courier/Delivery, Medicine Delivery and over 700 top brands. Also get products from Amazon & Ebay via Kapruka Gloabal Shop into Sri Lanka

Add comment

Comments will be edited (grammar, spelling and slang) and authorized at the discretion of Daily Mirror online. The website also has the right not to publish selected comments.

Reply To:

Name - Reply Comment




Order Gifts and Flowers to Sri Lanka. See Kapruka's top selling online shopping categories such as Toys, Grocery, Kids Toys, Birthday Cakes, Fruits, Chocolates, Clothing and Electronics. Also see Kapruka's unique online services such as Money Remittence,Astrology, Courier/Delivery, Medicine Delivery and over 700 top brands. Also get products from Amazon & Ebay via Kapruka Gloabal Shop into Sri Lanka