ESET has detected Win32/Filecoder.AESNI.C and also known as XData ransomware. The threat has been most prevalent in Ukraine, with 96% of the total detections between May 17 and May 22. The ransomware appears to have been distributed through a Ukrainian document automation system widely used in accounting. ESET protects its customers against this threat since May 18. If executed with admin privileges, the ransomware can infect an entire network. If youre interested in why the threat is called AESNI, it is derived from the ransom note dropped by one of its previous variants.”]

