New “Agenda” Ransomware Allow Attackers Customize Payloads for Each Victim

Share post:

Researchers from Trend Micro have uncovered Agenda, a new ransomware strain written in Golang that is used in the wild to target health and education facilities in Indonesia, Saudi Arabia, South Africa and Thailand.

A threat actor identified as Qilin is advertising the ransomware on the dark web. Qilin claims the ransomware offers affiliates the ability to customize the binary payloads for each victim.

This feature allows the operators to decide on the ransom note, the encryption extension and the list of processes and services that must be terminated before the encryption process begins.

The ransomware also has techniques for detection evasion. The techniques use the ‘safe mode’ feature of a device to continue with its file encryption undetected, but not before the password of the user is changed and an automatic login is enabled.

Agenda also has a unique feature that makes it possible to infect an entire network and its shared drivers.

After successful encryption Agenda renames the files with the configured extension, places the ransom note in each encrypted directory and restarts the computer in normal mode.

Although the ransom demanded by the attackers varies from company to company, the ransom demanded is estimated at US$50,000 to US$800,000.

The sources for this piece include an article in TheHackerNews.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Windows 11 upgrades for previously blocked PCs

Microsoft has finally resolved a longstanding issue that prevented certain PCs from upgrading to Windows 11. The compatibility...

AI-powered wearable “AI Pin” is savaged by tech reviewers

Humane's newly launched AI wearable, 'AI Pin,' envisioned to revolutionize the human-tech interface, has faced a barrage of...

Cisco Duo’s Multifactor Authentication service compromised by social engineering attack

Cisco Duo, a prominent provider of multifactor authentication (MFA) services, has fallen victim to a cyberattack targeting one...

Cyber Security Today, April 17, 2024 – More suspicious attempts to take over open source projects, a data theft at a Cisco Duo partner,...

This episode reports on security updates from Delinea and PuTTY, and reports on bad bots and threat actors going after Zoo

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways