Uptime Hamster: 11d 11h 35mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Offline ransomware

Offline ransomware

0 incidentes 0 paises 0 sectores ransomware RU Ultimo: -
Ver en IntelTracker → APTTrail →
Offline ransomware emerged in early 2015, notably characterized by its ability to encrypt files on a victim's system without requiring an active internet connection or communication with a command-and-control (C&C) server, which is an external server used by attackers to manage their malware. This ransomware variant operates by locally generating encryption keys, eliminating the typical network-based key exchange and allowing it to function effectively in isolated or air-gapped network environments. Its primary motivation is financial extortion, with attackers demanding payment for decryption. A distinguishing feature of this ransomware is its implementation using Pascal-based languages and Delphi for its core encryption routines, alongside a Visual Basic compiled protector for its payload. Symantec has identified specific versions of this ransomware under the alias Ransomcrypt.U.

Actores similares

lockbit3ransomware · 2016qilinransomware · 1933akiraransomware · 1524playransomware · 1268clopransomware · 1254lockbit2ransomware · 1002ransomhubransomware · 842incransomransomware · 832alphvransomware · 731dragonforceransomware · 580
Tipo
ransomware
Pais origen
RU
Motivacion
-
Impacto
56
Actualizado
Sat, 20 Ju

Paises objetivo (SOCRadar)

AustraliaBrazilCanadaChinaGermanyFranceUnited KingdomIndiaJapanRussian Federation

Sectores objetivo (SOCRadar)

AccommodationManufacturingConstructionPublic AdministrationOil & GasEducational ServicesInternet PublishingSpace & DefenseEnergy & Utilities Insurance