KeyPass, a new variant of the STOP ransomware, has been detected across 20 countries in the last two weeks. Researchers still arent sure exactly how it spreads. The most likely infection vector is fake installers, possibly used for software cracks or other gray market programs, Kaspersky Lab says. Since the ransomware infects both local drives and network shares while avoiding specific directories, such as those for Internet Explorer or Google, users may not notice the problem until the 72-hour window for cheap decryption has already expired.”]
Source: https://securityintelligence.com/news/keypass-ransomware-encrypts-data-across-20-countries/