Skip to content

Malware

Egregor

According to Heimdal, Egregor ransomware infection happens via a loader, then, in the victim’s firewall, it enables the Remote Desktop Protocol.

Egregor is a Windows malware family.

Background

Per Heimdal, an Egregor ransomware infection begins with a loader, after which the malware turns on the Remote Desktop Protocol in the victim's firewall. From there it can move laterally through the network, locating and shutting down any antivirus software it encounters. It then encrypts the data and drops a ransom note called "RECOVER-FILES.txt" into every affected folder.


Source: Malpedia (Fraunhofer FKIE).