• Cyber Security
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware File Recovery
    • Ransomware Types
  • Ransomware Services
    • Ransomware Removal
    • Ransomware File Recovery
  • News
  • Tutorials
  • Ransomware TV

Dragnea Ransomware: A Romanian Cryptovirological Threat

August 29, 2018Simeon Georgiev

Every second day a new ransomware strain appears on the block. This is a demonstration of the fact that cryptovirological operators are not slowing down and are constantly challenging the cyber security and ransomware removal measures devised by security experts. Malware hunters have recently discovered a new ransomware through compromised web links called Dragnea.

Initial investigations suggest that the ransomware locks the screen of the affected device. Researchers are still trying to find out whether its cryptovirological activity also affects the stored files on the device. All the details gathered by the security researchers regarding its activity are given below.

  • Dragnea ransomware penetrates into Windows registry files to develop the quality of persistence in its activity. In simple words, this trait of Dragnea ransomware enables it to lock down the screen every time the affected device is switched on.
  • Since Dragnea ransomware locks down the screen, therefore the ransom note directly appears on the display. It is worth mentioning that the ransom note is written in the Romanian language. It notifies the affected user that all the files stored on their device are locked and will be deleted soon if they don’t pay a ransom of $100.

Security Experts and Law Enforcement Agencies Advise Against Ransom Payment

Affected users are strongly advised against payment of extortion money to the attackers for ransomware removal. There is no guarantee that they would provide the decryption key after receiving the ransom. In addition, ransom payments might result in the encouragement of more such activities.

As it stands, Dragnea ransomware is in its budding phase. Therefore, researchers are still trying to work out an effective ransomware removal action for this cryptovirological strain. It would be better to get in touch with some professional ransomware removal experts following such attacks instead of playing into the hands of cryptovirological operators.

Simeon Georgiev
https://www.linkedin.com/in/simeon--georgiev/
I am a Cyber Security Enthusiast from Bulgaria. I like to write about malware and ransomware and global cyber attacks. You can reach me on Twitter @sgeorgiev1995 or Email: [email protected]
Previous post Eight Percent of Global Ransomware Attacks Affect Vietnamese Users Next post WORM: An Old and Reliable Storage Option for Ransomware Recovery

Related Articles

A Close Look at Cybersecurity Trends in 2018

February 16, 2018Simeon Georgiev
A Close Look at Cybersecurity Trends in 2018

Equifax’s Former CIO Found Guilty of Charges Related to Insider Trading

March 17, 2018Simeon Georgiev
Equifax’s Former CIO Found Guilty of Charges Related to Insider Trading

KwaakLocked – A Ransomware You Should Be Careful of

July 5, 2018Simeon Georgiev
kwaaklocked

Latest on Ransomware TV

https://vimeo.com/399908876?loop=0

Recent Posts

  • How to protect your organization against ransomware reinfections
  • AuKill Helps Ransomware Operators Disable EDR and Security Tools
  • AI-ransomware is a real threat, just not a realistic one yet
  • Rorschach is the new speed king in the ransomware space
  • The Role of Supply Chain Breaches in Ransomware Attacks

Stay Protected

Subscribe to our mailing list to get the latest cyber security and ransomware removal articles!

Thank you for subscribing.

Something went wrong.

Navigation

  • Cyber Security
    • Ransomware File Recovery
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware Types
  • News
  • Tutorials

Ransomware Attacks (Last 6M)

0

Connect & Protect

Facebook
Google+
LinkedIn
YouTube
Vimeo

More

  • BECOME A CONTRIBUTOR

MonsterCloud Reviews

© 2020 MonsterCloud.com. All Rights Reserved.