Black Ruby
Aliases: BlackRuby
- First seen
- 2018-02-06 00:00:00
- Malware type
- ransomware, cryptominer
- Family
- Malware family
- Profile updated
- 2026-07-07 13:41:42
Context
A new ransomware was discovered this week by MalwareHunterTeam called Black Ruby. This ransomware will encrypt the files on a computer, scramble the file name, and then append the BlackRuby extension. To make matters worse, Black Ruby will also install a Monero miner on the computer that utilizes as much of the CPU as it can. Discovered on February 6, 2018. May have been distributed through unknown vectors. Will not encrypt a machine if its IP address is identified as coming from Iran; this feature enables actors to avoid a particular Iranian cybercrime law that prohibits Iran-based actors from attacking Iranian victims. Encrypts files on the infected machine, scrambles files, and appends the .BlackRuby extension to them. Installs a Monero miner on the infected computer that utilizes the machine’s maximum CPU power. Delivers a ransom note in English asking for US$650 in Bitcoins. Might be installed via Remote Desktop Services.
Reports & references
- bleepingcomputer.com — Black Ruby Ransomware Skips Victims In Iran And Adds A Miner For Good Measure (report)
- accenture.com — Accenture Cyber Threatscape Report 2018 (report)