• Cyber Security
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware File Recovery
    • Ransomware Types
  • Ransomware Services
    • Ransomware Removal
    • Ransomware File Recovery
  • News
  • Tutorials
  • Ransomware TV

Tron ransomware: Another Dharma variant

November 23, 2018Simeon Georgiev

Tron ransomware is a newly discovered cryptovirological strain that is targeting English speaking users. According to initial investigations, the variant belongs to the Dharma ransomware family. Dharma has been an active ransomware strain since 2016 and inflicted considerable damage to users all across the globe.

Tron, like other variants of Dharma, uses Advanced Encryption module to lock down the files on the affected device. The encrypted files are then appended with a long extension that contains the attacker’s ID and the word ‘Tron’.

A unique ransom note

In most of the ransomware attacks, the ransom note appears on the desktop screen or in every folder in text or HTML file format. However, Tron operators have taken quite a different approach with the display of ransom note. Instead of finding the note in a separate file, the affected users are redirected to the window of instructions whenever they click on an encrypted file.

As per these instructions, the targeted users are asked to get in contact with the operators for ransomware removal within 10 days after the attack. The attackers also warn that the affected users won’t be able to recover their encrypted data after the expiration of this deadline. Moreover, they demand 0.05 Bitcoin, which is equal to $400 according to the current exchange rate, to provide decryption key for ransomware removal. They also guide victims on how to purchase Bitcoins.

Dharma attacks are on the rise

Cybersecurity experts have seen a sudden rise in Dharma ransomware activity during this fall. In the last 3 months, five Dharma variants have been discovered. Apart from Tron, the recently discovered Dharma variants are Gamma, Xxxxx, Brr and Audit ransomware.

Security experts and law enforcement entities always advise against engaging with the perpetrators for ransomware removal.  The best way to deal with ransomware attacks is to maintain data backups and get expert professional assistance.

Simeon Georgiev
https://www.linkedin.com/in/simeon--georgiev/
I am a Cyber Security Enthusiast from Bulgaria. I like to write about malware and ransomware and global cyber attacks. You can reach me on Twitter @sgeorgiev1995 or Email: [email protected]
Previous post Anti-virus Tools and the Apple Ecosystem Fail Against the Ransomware Terror Next post Decryption tool for some Gandcrab variants is now available

Related Articles

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

January 27, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

Ransomware: 4 Types of the Latest Trend in Cybercrimes

February 1, 2018Simeon Georgiev
Ransomware: 4 Types of the Latest Trend in Cybercrimes

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

February 1, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

Latest on Ransomware TV

https://vimeo.com/399908876?loop=0

Recent Posts

  • How to protect your organization against ransomware reinfections
  • AuKill Helps Ransomware Operators Disable EDR and Security Tools
  • AI-ransomware is a real threat, just not a realistic one yet
  • Rorschach is the new speed king in the ransomware space
  • The Role of Supply Chain Breaches in Ransomware Attacks

Stay Protected

Subscribe to our mailing list to get the latest cyber security and ransomware removal articles!

Thank you for subscribing.

Something went wrong.

Navigation

  • Cyber Security
    • Ransomware File Recovery
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware Types
  • News
  • Tutorials

Ransomware Attacks (Last 6M)

0

Connect & Protect

Facebook
Google+
LinkedIn
YouTube
Vimeo

More

  • BECOME A CONTRIBUTOR

MonsterCloud Reviews

© 2020 MonsterCloud.com. All Rights Reserved.