Sigrun Ransomware
- First seen
- 2018-05-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:42:18
Context
When Sigrun is executed it will first check "HKEY_CURRENT_USER\Keyboard Layout\Preload" to see if it is set to the Russian layout. If the computer is using a Russian layout, it will not encrypt the computer and just delete itself. Otherwise Sigrun will scan a computer for files to encrypt and skip any that match certain extensions, filenames, or are located in particular folders.
Reports & references
- bleepingcomputer.com — Sigrun Ransomware Author Decrypting Russian Victims For Free (report)
- id-ransomware.blogspot.com — Sigrun Ransomware (report)