Skip to content

Malware

7ev3n

The NJCCIC describes 7ev3n as a ransomware "that targets the Windows OS and spreads via spam emails containing malicious attachments, as well as file sharing networks.

7ev3n is a Windows malware family.

Background

7ev3n is a ransomware family targeting Windows systems, propagating through malicious attachments in spam email campaigns and via file-sharing networks. Once active, it drops several files into the LocalAppData folder, with each handling a distinct task such as turning off boot recovery options, removing its own installer, encrypting files, and elevating to administrator privileges. According to the NJCCIC, the variant also writes registry keys that disable a range of Windows function and control keys, including F1, F3, F4, F10, Alt, Num Lock, Ctrl, Enter, Escape, Shift, and Tab. Encrypted files receive the .R5A extension, and because the malware blocks access to Windows recovery options, undoing its damage proves difficult.


Source: Malpedia (Fraunhofer FKIE).