Threat intelligence, Threat Research

Hog ransomware decrypts victims who join their Discord server spreading in the wild

by Security News

The SonicWall Capture Labs Threat Research team observed reports of a new variant family of Hog ransomware actively spreading in the wild.

The Hog ransomware encrypts the victim's files with a strong encryption algorithm and only decrypts them if they join the developer's Discord server.

Infection Cycle:

The ransomware adds the following files to the system:

  • Malware.exe
    • %App.path%\ . Hog

Once the computer is compromised, the ransomware runs the following commands:

When Hog is started it will create and assign a unique ID number to the victim then scan all local drives for data files to encrypt.

When encrypting files it will use the AES encryption algorithm and encrypt all files except following extensions:

.exe .dll .ini .scr .sys .vmx .vmdk

The ransomware encrypts all the files and appends the [.Hog] extension onto each encrypted file's filename.

 

If the victim has joined the Discord server the ransomware will decrypt the victims' files using a static key embedded in the ransomware.

After encrypting all personal documents, the ransomware shows the following page containing a message reporting that the computer has been encrypted and how to unlock the files.

SonicWall Capture Labs provides protection against this threat via the following signature:

  • GAV: HogRansom.RSM (Trojan)

This threat is also detected by SonicWall Capture ATP w/RTDMI and the Capture Client endpoint solutions.

Share This Article

An Article By

Security News

The SonicWall Capture Labs Threat Research Team gathers, analyzes and vets cross-vector threat information from the SonicWall Capture Threat network, consisting of global devices and resources, including more than 1 million security sensors in nearly 200 countries and territories. The research team identifies, analyzes, and mitigates critical vulnerabilities and malware daily through in-depth research, which drives protection for all SonicWall customers. In addition to safeguarding networks globally, the research team supports the larger threat intelligence community by releasing weekly deep technical analyses of the most critical threats to small businesses, providing critical knowledge that defenders need to protect their networks.

Related Articles

  • SonicWall 2024年版サイバー脅威レポート中間アップデート:IoTの狂騒、PowerShellの問題など
    Read More
  • サイバー犯罪者の思考を探る:SonicWall、新たなサイバー攻撃に関するデータや脅威アクターの動作を最新レポートで解明
    Read More
  • Wind RiverのVxWorksおよびURGENT/11について – 今すぐパッチを適用してください
    Read More