Vietnamese ransomware wants you to add credit to a mobile phone
ID: 6cf1a448-c0fd-50a2-86b3-1497973f5a31
STIX ID: report--6cf1a448-c0fd-50a2-86b3-1497973f5a31
Feed Name: Blaze's Security Blog
**BKRansomware** is a simplistic Vietnamese ransomware that displays a ransom note demanding a Viettel mobile top-up to 0963210438, targets specific file extensions (.txt, .cpp, .docx, .bmp, .doc, .pdf, .jpg, .pptx, .png, .c, .py, .sql), appends the .hainhc extension, and merely ROT23-encodes file content instead of truly encrypting it; a debug path indicates Visual Studio-based development, and an update suggests the sample may have been used for testing, with references to associated keyloggers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
