Sage 2.0 Ransomware

First seen
2017-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:26:05

Targeted industries: education-and-nonprofits financial-services healthcare-and-pharmaceutical retail-and-hospitality

Context

It’s directed to English speaking users, therefore is able to infect worldwide. This ransomware attacks your MS Office by offering a Micro to help with your program, but instead incrypts all your files if the used id not protected. Predecessor CryLocker

Reports & references

  • id-ransomware.blogspot.co.il — Sage 2 Ransomware (report)
  • isc.sans.edu — 21959 (report)
  • securityweek.com — Sage 20 Ransomware Demands 2000 Ransom (report)
  • bleepingcomputer.com — Sage 2 0 Ransomware Gearing Up For Possible Greater Distribution (report)
  • govcert.admin.ch — Sage 2.0 Comes With Ip Generation Algorithm Ipga (report)

External references