Proton Ransomware
0 incidentes
0 paises
0 sectores
ransomware Global Ultimo: -
Aliases: Proton Locker
Proton Ransomware is a financially motivated cybercriminal group that emerged in March 2023, primarily targeting Windows systems to encrypt files and demand ransom. The group has undergone several iterations and rebranding, introducing new variants such as Zola, Shinra, Ripa, Cipher, Limba, and Matrix. While initial samples utilized ECC and AES-GCM encryption, later variants, starting in September 2023, switched to ChaCha20. The group is assessed with moderate confidence to be of Iranian origin, partly due to the Zola variant's inclusion of a kill switch that checks for a Persian keyboard layout. Proton Ransomware distinguishes itself by employing a dual extortion model, encrypting victim files and threatening to leak stolen sensitive data, and has been observed using misleading ransom notes that may claim older encryption algorithms despite implementing newer ones. It should not be confused with the unrelated PrOToN/Xorist ransomware.
Paises objetivo (SOCRadar)
Australia
Bulgaria
Brazil
China
Germany
Estonia
Spain
France
United Kingdom
Hong Kong
Sectores objetivo (SOCRadar)
Software PublishersEnterprises & HoldingAir TransportationManufacturingPublic AdministrationEducational ServicesWholesale TradeInsurancePublishing ServicesTelecommunications