XiaoBa

First seen
2018-03-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:42:09

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Context

XiaoBa is a type of ransomware known for encrypting files on the victim's system and demanding a ransom for decryption keys. It has targeted a range of industries, impacting their operations by restricting access to data and systems. XiaoBa is part of the growing trend of ransomware attacks affecting sectors worldwide.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Xiaoba_Auto (yara-rule)

Reports & references

  • id-ransomware.blogspot.com — Xiaoba Ransomware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Xiaoba (report)

External references