Rapid Ransom

First seen
2022-01-15 00:00:00
Malware type
ransomware
Profile updated
2026-07-07 13:44:56

Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing government-and-public-sector technology-and-telecommunications

Context

InfinityGroup notes that Rapid Ransomware, unlike regular Ransomware, stays active on the computer after initially encrypting the systems and also encrypts any new files that are created. It does this by creating auto-runs that are designed to launch the ransomware and display the ransom note every time the infected system is started.

Reports & references

  • youtube.com — Watch (report)
  • fsec.or.kr — 2297.Do (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Rapid Ransom (report)
  • twitter.com — 997748495888076800 (report)
  • exchange.xforce.ibmcloud.com — Guesswho Ransomware A Variant Of Rapid Ransomware Ef226B9792Fa4C1E34Fa4C587Db04145 (report)
  • twitter.com — 977275481765613569 (report)

External references