RSAUtil

Aliases: Vagger, DONTSLIP

First seen
2018-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:41:31

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical financial-services

Context

RSAUtil is distributed by the developer hacking into remote desktop services and uploading a package of files. This package contains a variety of tools, a config file that determines how the ransomware executes, and the ransomware itself.

Reports & references

  • securityweek.com — Rsautil Ransomware Distributed Rdp Attacks (report)
  • bleepingcomputer.com — Rsautil Ransomware Helppme India Com Installed Via Hacked Remote Desktop Services (report)
  • id-ransomware.blogspot.lu — Rsautil Ransomware (report)
  • id-ransomware.blogspot.lu — 04 (report)

External references