Beware: DJVU Ransomware's New 'Xaro' Variant Masquerades as Cracked Software

1 min read
Source: The Hacker News
Beware: DJVU Ransomware's New 'Xaro' Variant Masquerades as Cracked Software
Photo: The Hacker News
TL;DR Summary

A new variant of the DJVU ransomware, named Xaro, is being distributed disguised as cracked software. This variant appends the .xaro extension to affected files and demands a ransom for decryption. Xaro is delivered as a payload of SmokeLoader and is propagated through an archive file from a dubious source posing as a legitimate freeware site. The attack chain involves the deployment of additional malware, including information stealers like RedLine Stealer and Vidar. Xaro encrypts files, drops a ransom note, and demands a payment of $980 for the private key and decryptor tool. The use of cracked software and freeware from untrusted sources increases the risk of such attacks.

Share this article

Reading Insights

Total Reads

0

Unique Readers

8

Time Saved

2 min

vs 3 min read

Condensed

76%

452109 words

Want the full story? Read the original article

Read on The Hacker News