KillDisk Ransomware

First seen
2016-12-01 00:00:00
Malware type
ransomware, wiper
Family
Malware family
Profile updated
2026-07-07 13:28:08

Context

It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Every file is encrypted with a personal AES-key, and then AES-key encrypts with a RSA-1028 key. Hacking by TeleBots (Sandworm). Goes under a fake name: Update center or Microsoft Update center.

Reports & references

  • id-ransomware.blogspot.co.il — Killdisk Ransomware (report)
  • bleepingcomputer.com — Killdisk Ransomware Now Targets Linux Prevents Boot Up Has Faulty Encryption (report)
  • bleepingcomputer.com — Killdisk Disk Wiping Malware Adds Ransomware Component (report)
  • zdnet.com — 247000 Killdisk Ransomware Demands A Fortune Forgets To Unlock Files (report)
  • securityweek.com — Destructive Killdisk Malware Turns Ransomware (report)
  • ESET — Killdisk Now Targeting Linux Demands 250K Ransom Cant Decrypt (report)
  • cyberx-labs.com — New Killdisk Malware Brings Ransomware Into Industrial Domain (report)

External references