XiaoBa
- First seen
- 2018-03-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:42:09
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications
Context
XiaoBa is a type of ransomware known for encrypting files on the victim's system and demanding a ransom for decryption keys. It has targeted a range of industries, impacting their operations by restricting access to data and systems. XiaoBa is part of the growing trend of ransomware attacks affecting sectors worldwide.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Xiaoba_Auto (yara-rule)
Reports & references
- id-ransomware.blogspot.com — Xiaoba Ransomware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Xiaoba (report)