Jump to content

New ransomware only decrypts victims who join their Discord server


mood

Recommended Posts

New ransomware only decrypts victims who join their Discord server

 

discord-header-l.jpg

 

A new ransomware called 'Hog' encrypts users' devices and only decrypts them if they join the developer's Discord server.

 

This week, security researcher MalwareHunterTeam found an in-development decryptor for the Hog Ransomware that requires victims to join their Discord server to decrypt their files.

 

BleepingComputer was later able to find the encryptor component [VirusTotal] for the ransomware, which, when executed, will check if a particular Discord server exists, and if it does, begins to encrypt the victims' files.

 

When encrypting a victims' files, it will append the .hog extension as shown below and automatically extract the decryptor component.

 

encrypted-files.jpg

Hog Ransomware encrypted files

 

Once the ransomware has finished encrypting the device, it will launch the DECRYPT-MY-FILES.exe decryptor program from the Windows Startup folder.

 

This decryptor will explain what happened to the victims and then prompt them to enter their Discord user token.

 

hog-ranomware-decryptor.jpg

Hog Ransomware Decryptor

 

A Discord token allows the ransomware to authenticate to Discord's APIs as the user and check if they joined their server, as shown by the source code below.

 

source-code.jpg

Source code to check if the victim joined the Discord server

 

If the victim has joined the server or the server does not exist, the ransomware will decrypt the victims' files using a static key embedded in the ransomware.

 

decryption-free.jpg

Ransomware decrypting for free

 

While this appears to be an in-development ransomware, it does illustrate how threat actors are beginning to use Discord more often for malicious activities.

 

Another ransomware known as Humble was recently discovered by Trend Micro that uses a webhook to post details about new victims to the threat actor's Discord server.

 

Also, Discord is commonly used by threat actors to distribute malware or harvest stolen data.

 

As threat actors turn to Discord, it is critical for administrators and network security tools to monitor Discord traffic for threats or other abnormal behavior.

 

 

Source: New ransomware only decrypts victims who join their Discord server

Link to comment
Share on other sites


  • Views 433
  • Created
  • Last Reply

Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...