Sigrun Ransomware

First seen
2018-05-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:42:18

Context

When Sigrun is executed it will first check "HKEY_CURRENT_USER\Keyboard Layout\Preload" to see if it is set to the Russian layout. If the computer is using a Russian layout, it will not encrypt the computer and just delete itself. Otherwise Sigrun will scan a computer for files to encrypt and skip any that match certain extensions, filenames, or are located in particular folders.

Reports & references

  • bleepingcomputer.com — Sigrun Ransomware Author Decrypting Russian Victims For Free (report)
  • id-ransomware.blogspot.com — Sigrun Ransomware (report)

External references