Vgod RANSOMWARE
Feb. 18, 2025, 8:54 a.m.
Description
A new ransomware strain called Vgod has been observed targeting Windows systems. It encrypts files, appending the '.Vgod' extension, and leaves a ransom note titled 'Decryption Instructions.txt'. The ransomware changes the desktop wallpaper and employs a double extortion model, threatening data exposure and financial extortion. It uses advanced encryption techniques and sophisticated evasion and persistence mechanisms, making detection and removal challenging. The threat highlights the need for proactive cybersecurity measures and robust incident response strategies to protect data integrity and prevent breaches.
Tags
Date
- Created: Feb. 18, 2025, 6:02 a.m.
- Published: Feb. 18, 2025, 6:02 a.m.
- Modified: Feb. 18, 2025, 8:54 a.m.
Indicators
- 241c3b02a8e7d5a2b9c99574c28200df2a0f8c8bd7ba4d262e6aa8ed1211ba1f
Attack Patterns
- Vgod
- T1542.003
- T1552.001
- T1010
- T1564.001
- T1574.002
- T1074
- T1027.002
- T1018
- T1497.001
- T1059.001
- T1548
- T1014
- T1114
- T1095
- T1518.001
- T1005
- T1573
- T1486
- T1129
- T1106
- T1082
- T1057
- T1496
- T1083
- T1071
- T1055
- T1036
- T1560
- T1112
- T1003