Blog | G5 Cyber Security

RSAUtil Ransomware (.helppme@india.com) Installed Via Hacked Remote Desktop Services

RSAUtil was discovered by Emsisoft malware researcher xXToffeeXx. Ransomware is distributed by the developer hacking into remote desktop services and uploading a package of files. This package contains a variety of tools, a config file that determines how the ransomware executes, and the ransomware itself. While this ransomware is currently not decryptable for free, it may be in the future. If you wish to discuss this ransomware or receive support, you can use the dedicated RSA Util Help & Support topic in our forums.

Source: https://www.bleepingcomputer.com/news/security/rsautil-ransomware-helppme-india-com-installed-via-hacked-remote-desktop-services/

Exit mobile version