Erebus Ransomware

First seen
2016-09-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:32:31

Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality

Context

It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. After the files are decrypted, the shadow files are deleted using the following command: vssadmin.exe Delete Shadows /All /Quiet

Reports & references

  • id-ransomware.blogspot.co.il — Erebus Ransomware (report)

External references