Skip to content

Ransomware

Rapid Ransom

InfinityGroup notes that Rapid Ransomware, unlike regular Ransomware, stays active on the computer after initially encrypting the systems and also encrypts any new files that are created.

Rapid Ransom is a Windows ransomware.

Background

InfinityGroup observes that Rapid Ransomware differs from typical ransomware by remaining resident on the machine after its initial encryption pass, continuing to encrypt any newly created files. It achieves this by setting up auto-run entries that relaunch the ransomware and present the ransom note each time the compromised system boots.


Source: Malpedia (Fraunhofer FKIE).