Ransomware

Novel Proton Ransomware Variant with Kill Switch Emerges

Cyber basics

Attacks with the Zola ransomware, which is the latest iteration of the Proton ransomware that initially appeared more than a year ago, have been launched since May, SC Media reports.

Despite also using Mimikatz and other hacking tools for initial compromise and creating a mutex following execution like its Proton ransomware predecessors, Zola has been updated to feature a kill switch that would terminate processes upon the detection of a Persian keyboard layout, according to an Acronis analysis.

Subsequent admin privilege checking, which was found in the original Proton payload but not in the Shinra sub-family discovered in April, was performed by Zola in systems without the keyboard layout. Zola also adopts the ChaCha20 encryption scheme initially introduced in Proton variants introduced last September, as well as disk overwriting functionality that was integrated into Proton in April. Such findings follow the emergence of the unrelated PrOToN/Xorist ransomware, which features different ransom notes, encrypted file extensions, and contact details.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

You can skip this ad in 5 seconds

Cookies

This website uses cookies to improve your experience, provide social media features and deliver advertising offers that are relevant to you.

If you continue without changing your settings, you consent to our use of cookies in accordance with our privacy policy. You may disable cookies.