GoZone ransomware accuses and threatens victims

Teilen:

A new ransomware dubbed GoZone is being leveraged by attackers that don’t seem to be very greedy: they are asking the victims to pay just $1,000 in Bitcoin if they want their files decrypted.

The ransom notes shown by the malware lay out another incentive for paying up: they claim that child sexual abuse material has been found on the targeted computer and urge the victim to pay to prevent being reported to the authorities.

The GoZone ransomware

According to SonicWall researchers, the ransomware is written in Go, and uses the Chacha20 and RSA algorithms to encrypt victims’ files, which get the .d3prU extension.

The infected computer is also innundated with ransom notes: a .txt one created in every directory where files have been encrypted as well as on the desktop; a .html one opened with the system’s default browser; and one in the form of an image, to replace the system’s wallpaper.

“The victim will be unable to change this wallpaper as the ability to update the background settings has now been disabled by the ransomware,” the researchers have discovered.

Aside from encrypting files, the ransomware has additional modular capabilities that allow it to:

  • Bypass and disable User Account Control (UAC) on Windows systems
  • Overwrite the system’s master boot record (MBR)
  • Hamstring the System Restore tool

In short, if victims don’t have a backup of their files that’s not located on the affected system, they are likely to lose them for good. Paying the ransom is not a reliable option, as the threat actor may not share the decryption key or the key might not work.

And it seems that the victims know this: The Bitcoin address provided by the threat actor for payments (bc1qwemkeh2vu5ftzgat3sk87gr4mlskw898xd6tk5) has a short transaction history that includes no transactions made in the last few months. However, this is a new threat and the situation might change.

Zeljka Zorz

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:50 pm, Feb. 2, 2025
Wetter-Symbol 8°C
L: 7° | H: 10°
klarer Himmel
Luftfeuchtigkeit: 69 %
Druck: 1022 mb
Wind: 7 mph S
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 6%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:37 am
Sonnenuntergang: 4:51 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
7° | 10°°C 0 mm 0% 6 mph 76 % 1025 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
2° | 9°°C 0 mm 0% 9 mph 89 % 1025 mb 0 mm/h
Di. Feb. 04 9:00 pm
Wetter-Symbol
7° | 11°°C 0.2 mm 20% 13 mph 89 % 1027 mb 0 mm/h
Mi. Feb. 05 9:00 pm
Wetter-Symbol
4° | 8°°C 0 mm 0% 10 mph 84 % 1045 mb 0 mm/h
Do. Feb. 06 9:00 pm
Wetter-Symbol
2° | 8°°C 0 mm 0% 8 mph 84 % 1045 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 6 mph 70 % 1022 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
5° | 7°°C 0 mm 0% 3 mph 71 % 1023 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
4° | 5°°C 0 mm 0% 3 mph 76 % 1025 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 3 mph 81 % 1025 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 4 mph 84 % 1025 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 4 mph 85 % 1025 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 4 mph 85 % 1025 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 7 mph 80 % 1025 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€95,153.36
-3.52%
Ethereum(ETH)
€2,961.86
-5.93%
XRP(XRP)
€2.69
-7.02%
Fesseln(USDT)
€0.96
-0.02%
Solana(SOL)
€203.25
-7.98%
USDC(USDC)
€0.96
0.00%
Dogecoin(DOGE)
€0.284179
-9.17%
Shiba Inu(SHIB)
€0.000016
-8.62%
Pepe(PEPE)
€0.000012
-9.93%
Nach oben scrollen