Cybercriminals are using the name of cybersecurity company Sophos in a new ransomware campaign. The ransomware used in the attack has been dubbed SophosEncrypt.
The MalwareHunterTeam first brought attention to the ransomware in a tweet on Monday. Sophos responded, saying it is aware of the ransomware and has been investigating it.
Sophos shed more light on the ransomware in a report on Tuesday, describing it as novel and “unusually retro in terms of its functionality.”
According to Sophos, the capabilities of SophosEncrypt “falls closer to a general-purpose remote access trojan [RAT] with the capacity to encrypt files and generate these ransom notes, than to a contemporary ransomware executable.”
How SophosEncrypt Ransomware Works
The SophosEncrypt ransomware can be configured to encrypt particular files or all the files on a targeted device. It encrypts files using AES256-CBC encryption. When it encrypts files, it changes the file name to random strings of text and adds the suffix “.sophos” as a file extension. For example, a file named “report.docx” could become “3f2a9b8c.sophos.”
The ransomware then delivers a ransom note. The word “Sophos” appears both on the ransom panel and the device’s wallpaper after it has been encrypted.
While the attackers behind SophosEncrypt are using the Sophos brand name, their logo and color scheme are strikingly different from the branding of the Sophos cybersecurity company.
Sophos said the attackers require victims to contact them using methods that ransomware groups no longer use — email or via Jabber instant messenger.
Protecting Your Device From Ransomware
To protect your device from ransomware, it’s important to avoid opening suspicious attachments and use a good antivirus that can detect and block malware.
If you fall victim to a ransomware attack, organizations like No More Ransom provide free ransomware decryption tools. While there are no free decryption tools for SophosEncrypt at this time, researchers are working on creating one, and we’ll update this article once it is available.
