A new ransomware strain named VanHelsing has emerged, targeting Windows systems with sophisticated encryption techniques and advanced evasion tactics. Cyfirma researchers discovered that VanHelsing employs a double extortion strategy, not only encrypting files but also exfiltrating sensitive data such as personal details, financial reports, and other critical documents. Security experts recommend implementing robust backup solutions, enabling multifactor authentication, patching systems regularly, and employing zero-trust architecture to mitigate risks from this emerging threat. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. Upon infection, VanHelsing encrypts files on the victim’s system, appending the distinctive “.vanhelsing” extension to compromised files. The ransomware also changes the desktop wallpaper and drops a ransom note named “README.txt” to communicate with victims. VanHelsing utilizes numerous evasion tactics that make detection challenging for security solutions. The ransomware’s capabilities extend to credential theft, system discovery, and data collection from local systems and email repositories. Tushar is a Cyber security content editor with a passion for creating captivating and informative content. The ransomware modifies the victim’s desktop wallpaper with a branded message indicating the system has been compromised. VanHelsing operates a dedicated chat portal on the Tor network where victims can communicate with attackers. The ransomware’s technical sophistication is evident in its various persistence mechanisms and defense evasion techniques. The malware can modify registry settings, execute indirect commands, and manipulate file permissions to maintain persistence. For persistence, it employs registry run keys, Windows services, and bootkit capabilities.
This Cyber News was published on cybersecuritynews.com. Publication date: Fri, 21 Mar 2025 09:11:02 +0000